<?xml version='1.0' encoding='UTF-8'?>
<cce:cce_list xmlns='http://cce.mitre.org' xmlns:cce='http://cce.mitre.org' xmlns:dcterms='http://purl.org/dc/terms/' version='5.20130214' modified='2013-02-11'>
  <cces modified='2013-02-11'>
    <cce cce_id='CCE-5847-9' platform='aix5.3' modified='2009-04-30'>
      <description>/export/home should be configured on an appropriate filesystem logical volume</description>
      <parameters>
        <parameter>logical volume</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via fstab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.2.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5424-7' platform='aix5.3' modified='2009-04-30'>
      <description>/var should be configured on an appropriate filesystem logical volume</description>
      <parameters>
        <parameter>logical volume</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via fstab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.2.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5710-9' platform='aix5.3' modified='2009-04-30'>
      <description>/opt should be configured on an appropriate filesystem logical volume</description>
      <parameters>
        <parameter>logical volume</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via fstab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.2.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5662-2' platform='aix5.3' modified='2009-04-30'>
      <description>The shell for the root account should be located on the appropriate filesystem</description>
      <parameters>
        <parameter>filesystem</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.2.1 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5317-3' platform='aix5.3' modified='2009-04-30'>
      <description>Core dump size limits should be set appropriately</description>
      <parameters>
        <parameter>Size (0 to disable core dumps)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/limits</technical_mechanism>
        <technical_mechanism>via ulimit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.4 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5384-3' platform='aix5.3' modified='2009-04-30'>
      <description>The read-only SNMP community string should be set appropriately.</description>
      <parameters>
        <parameter>string</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/snmp.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (1) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5723-2' platform='aix5.3' modified='2009-04-30'>
      <description>The read/write SNMP community string should be set appropriately.</description>
      <parameters>
        <parameter>string</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/snmp.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (1) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5634-1' platform='aix5.3' modified='2009-04-30'>
      <description>Password policy should ban or allow usernames or UIDs in passwords as appropriate</description>
      <parameters>
        <parameter>ban/allow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5352-0' platform='aix5.3' modified='2009-04-30'>
      <description>Password policy should ban or allow words found in a dictionary as appropriate.</description>
      <parameters>
        <parameter>ban/allow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5848-7' platform='aix5.3' modified='2009-04-30'>
      <description>Password policy should enforce the correct amount of special characters</description>
      <parameters>
        <parameter>number of special characters</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5443-7' platform='aix5.3' modified='2009-04-30'>
      <description>Password policy should enforce or not enforce the requirement to have mixed case passwords as appropriate.</description>
      <parameters>
        <parameter>enforce/not enforce</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5664-8' platform='aix5.3' modified='2009-04-30'>
      <description>The minimum password age should be set as appropriate</description>
      <parameters>
        <parameter>number of days</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5804-0' platform='aix5.3' modified='2009-04-30'>
      <description>The minimum required password length should be set as appropriate</description>
      <parameters>
        <parameter>number of characters</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4858-7' platform='aix5.3' modified='2009-04-30'>
      <description>Password history should be saved for an appropriate number of password changes</description>
      <parameters>
        <parameter>number of password changes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) d)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5775-2' platform='aix5.3' modified='2009-04-30'>
      <description>The number of consecutive failed login attempts required to trigger a lockout should be set as appropriate</description>
      <parameters>
        <parameter>number of consecutive failed login attempts</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) e)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5761-2' platform='aix5.3' modified='2009-04-30'>
      <description>Login access to accounts without passwords should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via passwd</technical_mechanism>
        <technical_mechanism>via /etc/shadow</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5841-2' platform='aix5.3' modified='2009-04-30'>
      <description>New users should be required or not required to change their password on first login as appropriate</description>
      <parameters>
        <parameter>required/not required</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) g)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5858-6' platform='aix5.3' modified='2009-04-30'>
      <description>Access to single-user mode (maintainence mode) should require the root password or not as appropriate</description>
      <parameters>
        <parameter>required/not required</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5078-1' platform='aix5.3' modified='2009-04-30'>
      <description>The delay between failed logins should be set as appropriate</description>
      <parameters>
        <parameter>number of seconds</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5715-8' platform='aix5.3' modified='2009-04-30'>
      <description>All files should be owned by an existing account or not as appropriate.</description>
      <parameters>
        <parameter>existing account required / existing account not required</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5684-6' platform='aix5.3' modified='2009-04-30'>
      <description>All files should be owned by an existing group or not as appropriate.</description>
      <parameters>
        <parameter>existing group required / existing group not required</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5244-9' platform='aix5.3' modified='2009-04-30'>
      <description>The console login banner should be set appropriately.</description>
      <parameters>
        <parameter>banner text or null</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/login.cfg</technical_mechanism>
        <technical_mechanism>via /etc/motd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (5) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5402-3' platform='aix5.3' modified='2009-04-30'>
      <description>The SSH login banner should be set appropriately.</description>
      <parameters>
        <parameter>banner text or null</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via sshd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (5) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5622-6' platform='aix5.3' modified='2009-04-30'>
      <description>The telnet login banner should be set appropriately.</description>
      <parameters>
        <parameter>banner text or null</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (5) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5843-8' platform='aix5.3' modified='2009-04-30'>
      <description>The ftp login banner should be set appropriately.</description>
      <parameters>
        <parameter>banner text or null</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (5) d)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5842-0' platform='aix5.3' modified='2009-04-30'>
      <description>The graphical login banner should be set appropriately.</description>
      <parameters>
        <parameter>banner text or null</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (5) e)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5560-8' platform='aix5.3' modified='2009-04-30'>
      <description>Accounts other than root should be allowed to have the UID 0 or not as appropriate</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via passwd</technical_mechanism>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.1 (2) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4873-6' platform='aix5.3' modified='2009-04-30'>
      <description>Accounts other than root and locked system accounts should be allowed to have a GID of 0 or not as appropriate</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via passwd</technical_mechanism>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.1 (2) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5187-0' platform='aix5.3' modified='2009-04-30'>
      <description>Each account should be assigned a unique UID or not as appropriate</description>
      <parameters>
        <parameter>unique/not unique</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.4 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5765-3' platform='aix5.3' modified='2009-04-30'>
      <description>The ftp account should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.4 (9)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4884-3' platform='aix5.3' modified='2009-04-30'>
      <description>Login accounts should include an appropriate GECOS identifier or no GECOS identifier</description>
      <parameters>
        <parameter>GECOS value, null</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.4.1 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5381-9' platform='aix5.3' modified='2009-04-30'>
      <description>The screen lock should activate after an appropriate period of inactivity</description>
      <parameters>
        <parameter>number of minutes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via Xscreensaver</technical_mechanism>
        <technical_mechanism>via dtsession</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.5 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5645-7' platform='aix5.3' modified='2009-04-30'>
      <description>File permissions should be set appropriately for all shell executables.</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5597-0' platform='aix5.3' modified='2009-04-30'>
      <description>Remote (serial) consoles should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via BIOS</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5676-2' platform='aix5.3' modified='2009-04-30'>
      <description>Root logins should be restricted to the console or not as appropriate.</description>
      <parameters>
        <parameter>restricted/not restricted</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>/etc/default/login</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (4)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5733-1' platform='aix5.3' modified='2009-04-30'>
      <description>.netrc files should exist or not as appropriate for all users.</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5702-6' platform='aix5.3' modified='2009-04-30'>
      <description>.rhosts files should exist or not as appropriate for all users.</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5076-5' platform='aix5.3' modified='2009-04-30'>
      <description>.shosts files should exist or not as appropriate for all users.</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5442-9' platform='aix5.3' modified='2009-04-30'>
      <description>The /etc/hosts.equiv file should exist or not as appropriate.</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5640-8' platform='aix5.3' modified='2009-04-30'>
      <description>The use of NIS special characters  (+ or -) in the first field of the /etc/passwd file should be allowed or disallowed as appropriate.</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Text editor</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (7)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4893-4' platform='aix5.3' modified='2009-04-30'>
      <description>The use of NIS special characters  (+ or -) in the first field of the /etc/shadow file should be allowed or disallowed as appropriate.</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Text editor</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (7)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5024-5' platform='aix5.3' modified='2009-04-30'>
      <description>The use of NIS special characters  (+ or -) in the first field of the /etc/group file should be allowed or disallowed as appropriate.</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Text editor</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (10)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5742-2' platform='aix5.3' modified='2009-04-30'>
      <description>The /etc/shells file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Text editor</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (11)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5777-8' platform='aix5.3' modified='2009-04-30'>
      <description>Shells referenced in /etc/passwd should be included in /etc/shells or not as appropriate</description>
      <parameters>
        <parameter>included/not included</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>/etc/shells</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (12)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5605-1' platform='aix5.3' modified='2009-04-30'>
      <description>Groups referenced in /etc/passwd should be included in /etc/group or not as appropriate.</description>
      <parameters>
        <parameter>included/not included</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>/etc/group</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (15)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5750-5' platform='aix5.3' modified='2009-04-30'>
      <description>The home directory for the root account should be set appropriately.</description>
      <parameters>
        <parameter>path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>/etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (16)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5199-5' platform='aix5.3' modified='2009-04-30'>
      <description>The home directory for each user account should be set appropriately.</description>
      <parameters>
        <parameter>path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>/etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (17)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5310-8' platform='aix5.3' modified='2009-04-30'>
      <description>Home directories referenced in /etc/passwd should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (18)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5327-2' platform='aix5.3' modified='2009-04-30'>
      <description>All device files should be located inside an appropriate directory</description>
      <parameters>
        <parameter>path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (24)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4900-7' platform='aix5.3' modified='2009-04-30'>
      <description>The ntpd service should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.3 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5675-4' platform='aix5.3' modified='2009-04-30'>
      <description>The Network Time Protocol (ntp) synchronization server should be set appropriately.</description>
      <parameters>
        <parameter>timeserver</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>ntpd.conf</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-5147-4' platform='aix5.3' modified='2009-04-30'>
      <description>All logon attempts should be logged or not logged as appropriate</description>
      <parameters>
        <parameter>logged/not logged</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Audit subsystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.3 (4)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5724-0' platform='aix5.3' modified='2009-04-30'>
      <description>All su (switch user) activity should be logged or not as appropriate</description>
      <parameters>
        <parameter>logged/not logged</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Audit subsystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.3 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5614-3' platform='aix5.3' modified='2009-04-30'>
      <description>Filesystem logging/journaling should be performed or not as appropriate</description>
      <parameters>
        <parameter>performed/not performed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Audit subsystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.3 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5834-7' platform='aix5.3' modified='2009-04-30'>
      <description>Automount should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (12)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5745-5' platform='aix5.3' modified='2009-04-30'>
      <description>Source-routed packets should be accepted or rejected as appropriate.</description>
      <parameters>
        <parameter>accepted/rejected</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (2) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5587-1' platform='aix5.3' modified='2009-04-30'>
      <description>Response to ICMP timestamp requests should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (2) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5525-1' platform='aix5.3' modified='2009-04-30'>
      <description>Response to ICMP timestamp broadcast requests should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (2) d)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4930-4' platform='aix5.3' modified='2009-04-30'>
      <description>Response to ICMP echo (ping) requests should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (2) e)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4901-5' platform='aix5.3' modified='2009-04-30'>
      <description>Executable stack should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5017-9' platform='aix5.3' modified='2009-04-30'>
      <description>The default gateway should be set appropriately.</description>
      <parameters>
        <parameter>IP address/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/default/route.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (4)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5347-0' platform='aix5.3' modified='2009-04-30'>
      <description>The inetd service should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5193-8' platform='aix5.3' modified='2009-04-30'>
      <description>echo service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5725-7' platform='aix5.3' modified='2009-04-30'>
      <description>netstat service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5801-6' platform='aix5.3' modified='2009-04-30'>
      <description>rcp service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #3</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5506-1' platform='aix5.3' modified='2009-04-30'>
      <description>chargen service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5791-9' platform='aix5.3' modified='2009-04-30'>
      <description>finger service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5743-0' platform='aix5.3' modified='2009-04-30'>
      <description>tftpd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5773-7' platform='aix5.3' modified='2009-04-30'>
      <description>walld service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5461-9' platform='aix5.3' modified='2009-04-30'>
      <description>rstatd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #8</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4905-6' platform='aix5.3' modified='2009-04-30'>
      <description>sprayd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5463-5' platform='aix5.3' modified='2009-04-30'>
      <description>rusersd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5542-6' platform='aix5.3' modified='2009-04-30'>
      <description>rlogin service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5431-2' platform='aix5.3' modified='2009-04-30'>
      <description>rsh service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5780-2' platform='aix5.3' modified='2009-04-30'>
      <description>ftp service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5872-7' platform='aix5.3' modified='2009-04-30'>
      <description>telnet service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4909-8' platform='aix5.3' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5343-9' platform='aix5.3' modified='2009-04-30'>
      <description>inn service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5611-9' platform='aix5.3' modified='2009-04-30'>
      <description>uucp service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5598-8' platform='aix5.3' modified='2009-04-30'>
      <description>rexec service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #18</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5550-9' platform='aix5.3' modified='2009-04-30'>
      <description>inetd logging should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #19</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4911-4' platform='aix5.3' modified='2009-04-30'>
      <description>font-service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #20</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4926-2' platform='aix5.3' modified='2009-04-30'>
      <description>imap2 service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4913-0' platform='aix5.3' modified='2009-04-30'>
      <description>pop3 service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #22</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5681-2' platform='aix5.3' modified='2009-04-30'>
      <description>ident service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #23</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5368-6' platform='aix5.3' modified='2009-04-30'>
      <description>rexd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5549-1' platform='aix5.3' modified='2009-04-30'>
      <description>daytime service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #26</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5144-1' platform='aix5.3' modified='2009-04-30'>
      <description>dtspc (cde-spc) service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5223-3' platform='aix5.3' modified='2009-04-30'>
      <description>rquotad service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #28</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5738-0' platform='aix5.3' modified='2009-04-30'>
      <description>cmsd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #29</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5456-9' platform='aix5.3' modified='2009-04-30'>
      <description>tooltalk service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #30</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4918-9' platform='aix5.3' modified='2009-04-30'>
      <description>xdmcp service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #31</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5798-4' platform='aix5.3' modified='2009-04-30'>
      <description>discard service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #32</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4923-9' platform='aix5.3' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5917-0' platform='aix5.3' modified='2009-04-30'>
      <description>vino-server service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4934-6' platform='aix5.3' modified='2009-04-30'>
      <description>The bind service should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.1 (2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5535-0' platform='aix5.3' modified='2009-04-30'>
      <description>The version string reported by the bind service should be configured appropriately.</description>
      <parameters>
        <parameter>string</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/named.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5117-7' platform='aix5.3' modified='2009-04-30'>
      <description>SSH Protocol v1 should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>/etc/ssh/ssh_config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.2 (2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5690-3' platform='aix5.3' modified='2009-04-30'>
      <description>TCP_WRAPPERS should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.3 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5852-9' platform='aix5.3' modified='2009-04-30'>
      <description>SNMP version 1 should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.4 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5068-2' platform='aix5.3' modified='2009-04-30'>
      <description>The nfsd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5569-9' platform='aix5.3' modified='2009-04-30'>
      <description>The mountd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5806-5' platform='aix5.3' modified='2009-04-30'>
      <description>The statd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5882-6' platform='aix5.3' modified='2009-04-30'>
      <description>The lockd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5414-8' platform='aix5.3' modified='2009-04-30'>
      <description>NFS should be configured to respond or not as appropriate to client requests that do not include a user id .</description>
      <parameters>
        <parameter>respond/not respond</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5348-8' platform='aix5.3' modified='2009-04-30'>
      <description>NFS should be configured to respond or not as appropriate to client requests that do not originate from a privileged port.</description>
      <parameters>
        <parameter>respond/not respond</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5511-1' platform='aix5.3' modified='2009-04-30'>
      <description>NFS server support for the AUTH_NONE authentication mechanism should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5480-9' platform='aix5.3' modified='2009-04-30'>
      <description>NFS server support for the AUTH_UNIX authentication mechanism should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4957-7' platform='aix5.3' modified='2009-04-30'>
      <description>NFS server support for the AUTH_DES authentication mechanism should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4958-5' platform='aix5.3' modified='2009-04-30'>
      <description>NFS server support for the AUTH_KERB authentication mechanism should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5922-0' platform='aix5.3' modified='2009-04-30'>
      <description>The read-only (ro) option should be enabled or disabled as appropriate for all NFS exports.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/exports</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) g)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5790-1' platform='aix5.3' modified='2009-04-30'>
      <description>The nosuid option should be enabled or disabled for all NFS mounts as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/fstab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) i)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5189-6' platform='aix5.3' modified='2009-04-30'>
      <description>The nosgid option should be enabled or disabled for all NFS mounts as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/fstab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) i)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5876-8' platform='aix5.3' modified='2009-04-30'>
      <description>Sendmail should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4959-3' platform='aix5.3' modified='2009-04-30'>
      <description>The sendmail banner should be set appropriately.</description>
      <parameters>
        <parameter>string</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/mail/sendmail.cf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5115-1' platform='aix5.3' modified='2009-04-30'>
      <description>The decode sendmail alias should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/aliases</technical_mechanism>
        <technical_mechanism>via /usr/lib/aliases</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5445-2' platform='aix5.3' modified='2009-04-30'>
      <description>.forward files should be allowed or disallowed as appropriate for all users</description>
      <parameters>
        <parameter>allow/disallow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via rm</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) e)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4960-1' platform='aix5.3' modified='2009-04-30'>
      <description>Programs executed through the aliases file should be owned by an appropriate user</description>
      <parameters>
        <parameter>user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5802-4' platform='aix5.3' modified='2009-04-30'>
      <description>Programs executed through the aliases file should reside a directory with an appropriate user owner</description>
      <parameters>
        <parameter>user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5212-6' platform='aix5.3' modified='2009-04-30'>
      <description>Sendmail vrfy command should be allowed or not as appropriate</description>
      <parameters>
        <parameter>allow/disallow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/mail/sendmail.cf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) g)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5291-0' platform='aix5.3' modified='2009-04-30'>
      <description>Sendmail expn command should be allowed or not as appropriate</description>
      <parameters>
        <parameter>allow/disallow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/mail/sendmail.cf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) h)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5741-4' platform='aix5.3' modified='2009-04-30'>
      <description>Sendmail should be configured with an appropriate logging level</description>
      <parameters>
        <parameter>logging level</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/mail/sendmail.cf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) i)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4967-6' platform='aix5.3' modified='2009-04-30'>
      <description>The sendmail help command should be allowed or not as appropriate</description>
      <parameters>
        <parameter>allow/disallow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/mail/sendmail.cf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) k)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5783-6' platform='aix5.3' modified='2009-04-30'>
      <description>NIS should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.3 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4975-9' platform='aix5.3' modified='2009-04-30'>
      <description>NIS+ server should operate at an appropriate security level</description>
      <parameters>
        <parameter>security level</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via NIS+</technical_mechanism>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.3 (1) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5138-3' platform='aix5.3' modified='2009-04-30'>
      <description>X-Windows should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via Xwindows</technical_mechanism>
        <technical_mechanism>via /etc/inittab vi RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.4 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5711-7' platform='aix5.3' modified='2009-04-30'>
      <description>Authorized X-clients should be listed or not in the X*.hosts file as appropriate</description>
      <parameters>
        <parameter>listed/not listed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/X*.hosts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.4 (2) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4984-1' platform='aix5.3' modified='2009-04-30'>
      <description>X-Windows should write .Xauthority files to users' home directories or not as appropriate</description>
      <parameters>
        <parameter>write/not write</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via xdm</technical_mechanism>
        <technical_mechanism>via gdm</technical_mechanism>
        <technical_mechanism>via kdm</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.4 (2) d)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5975-8' platform='aix5.3' modified='2009-04-30'>
      <description>X11 forwarding via SSH should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via sshd_config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.4 (2) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5931-1' platform='aix5.3' modified='2009-04-30'>
      <description>Samba should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via smbd</technical_mechanism>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.6 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4994-0' platform='aix5.3' modified='2009-04-30'>
      <description>Samba 'hosts allow' option should be configured with an appropriate set of networks</description>
      <parameters>
        <parameter>list of networks</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via smbd</technical_mechanism>
        <technical_mechanism>via smb.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.6 (3) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5923-8' platform='aix5.3' modified='2009-04-30'>
      <description>Samba 'security option' option should be set as appropriate</description>
      <parameters />
      <technical_mechanisms>
        <technical_mechanism>via smbd</technical_mechanism>
        <technical_mechanism>via smb.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.6 (3) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5939-4' platform='aix5.3' modified='2009-04-30'>
      <description>Samba 'encrypt' passwords option should be set as appropriate</description>
      <parameters>
        <parameter>yes/no</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via smbd</technical_mechanism>
        <technical_mechanism>via smb.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.6 (3) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5891-7' platform='aix5.3' modified='2009-04-30'>
      <description>Samba 'smb passwd file' option should be set to an appropriate password file or no password file</description>
      <parameters>
        <parameter>file/nothing</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via smbd</technical_mechanism>
        <technical_mechanism>via smb.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.6 (3) d)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5234-0' platform='aix5.3' modified='2009-04-30'>
      <description>IPv6 should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via SMIT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.3 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5767-9' platform='aix5.3' modified='2009-04-30'>
      <description>The "at" utility directory permissions should be set as appropriate</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5846-1' platform='aix5.3' modified='2009-04-30'>
      <description>at.allow file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5991-5' platform='aix5.3' modified='2009-04-30'>
      <description>at.deny file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5705-9' platform='aix5.3' modified='2009-04-30'>
      <description>Cron directory permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5678-8' platform='aix5.3' modified='2009-04-30'>
      <description>Crontab directory permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5942-8' platform='aix5.3' modified='2009-04-30'>
      <description>Cron log file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5770-3' platform='aix5.3' modified='2009-04-30'>
      <description>cron.allow file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5280-3' platform='aix5.3' modified='2009-04-30'>
      <description>cron.deny file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5896-6' platform='aix5.3' modified='2009-04-30'>
      <description>Crontab file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #8</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5474-2' platform='aix5.3' modified='2009-04-30'>
      <description>/dev/kmem file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5363-7' platform='aix5.3' modified='2009-04-30'>
      <description>/dev/mem file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5566-5' platform='aix5.3' modified='2009-04-30'>
      <description>/dev/null file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5851-1' platform='aix5.3' modified='2009-04-30'>
      <description>resolv.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5821-4' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/named.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5755-4' platform='aix5.3' modified='2009-04-30'>
      <description>File permissions should be set appropriately for all user home directories.</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5807-3' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/exports file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #23</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5759-6' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/bin/at file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #25</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5979-0' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/bin/rdist file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #26</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5228-2' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/sbin/sync file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5951-9' platform='aix5.3' modified='2009-04-30'>
      <description>Superuser account home directories' permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #29</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5981-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/samba/smb.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #31</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5668-9' platform='aix5.3' modified='2009-04-30'>
      <description>smbpassword executable permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #32</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5010-4' platform='aix5.3' modified='2009-04-30'>
      <description>Aliases file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5666-3' platform='aix5.3' modified='2009-04-30'>
      <description>File permissions should be set as appropriate for the log file configured to capture critical sendmail messages.</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #35</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5012-0' platform='aix5.3' modified='2009-04-30'>
      <description>All files executed through /etc/aliases file entries should have file permissions set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #36</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5796-8' platform='aix5.3' modified='2009-04-30'>
      <description>/bin/csh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #37</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5747-1' platform='aix5.3' modified='2009-04-30'>
      <description>/bin/jsh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #38</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5849-5' platform='aix5.3' modified='2009-04-30'>
      <description>/bin/ksh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #39</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5893-3' platform='aix5.3' modified='2009-04-30'>
      <description>The /bin/rsh file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #40</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5734-9' platform='aix5.3' modified='2009-04-30'>
      <description>/bin/sh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #41</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5862-8' platform='aix5.3' modified='2009-04-30'>
      <description>/bin/bash file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #42</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5954-3' platform='aix5.3' modified='2009-04-30'>
      <description>/sbin/csh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #43</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5027-8' platform='aix5.3' modified='2009-04-30'>
      <description>/sbin/jsh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #44</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5206-8' platform='aix5.3' modified='2009-04-30'>
      <description>/sbin/ksh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #45</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5907-1' platform='aix5.3' modified='2009-04-30'>
      <description>The /sbin/rsh file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #46</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5040-1' platform='aix5.3' modified='2009-04-30'>
      <description>/sbin/sh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #47</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5049-2' platform='aix5.3' modified='2009-04-30'>
      <description>/sbin/bash file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #48</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5056-7' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/bin/csh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #49</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6031-9' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/bin/jsh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6004-6' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/bin/ksh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #51</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5974-1' platform='aix5.3' modified='2009-04-30'>
      <description>The /usr/bin/rsh file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #52</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5863-6' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/bin/sh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #53</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5815-6' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/bin/bash file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #54</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5955-0' platform='aix5.3' modified='2009-04-30'>
      <description>snmpd.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #56</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6052-5' platform='aix5.3' modified='2009-04-30'>
      <description>/tmp file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #57</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6021-0' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/tmp file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #58</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5272-0' platform='aix5.3' modified='2009-04-30'>
      <description>traceroute executable file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #59</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5884-2' platform='aix5.3' modified='2009-04-30'>
      <description>.Xauthority file permissions should be set appropriately for all users.</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #60</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6023-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/aliases file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #61</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5349-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/cron.d/at.allow file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #62</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6050-9' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/cron.d/cron.allow file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #63</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5833-9' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/csh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #64</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5803-2' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/default/* file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #65</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5820-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/default/login file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #66</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5397-5' platform='aix5.3' modified='2009-04-30'>
      <description>The /etc/ftpusers file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #69</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5226-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/host.lpd file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #70</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5903-0' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/hostname* file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #71</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5970-9' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/hosts file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #72</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5930-3' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/inetd.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #73</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5698-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/issue file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #75</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5641-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/jsh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #76</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5909-7' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/ksh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #77</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5985-7' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/mail/aliases file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #78</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5350-4' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/motd file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #79</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5988-1' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/netconfig file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #80</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5817-2' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/notrouter file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #81</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5231-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/pam.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #82</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5323-1' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/passwd file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #83</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5526-9' platform='aix5.3' modified='2009-04-30'>
      <description>The /etc/rsh file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #84</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5631-7' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/security file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #85</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5728-1' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/services file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #86</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5512-9' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/sh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #87</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5074-0' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/shadow file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #88</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5808-1' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/syslog.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #89</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5075-7' platform='aix5.3' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5932-9' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/fstab file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #91</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5825-5' platform='aix5.3' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5279-5' platform='aix5.3' modified='2009-04-30'>
      <description>/var/adm/loginlog file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #93</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5984-0' platform='aix5.3' modified='2009-04-30'>
      <description>/var/adm/messages file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #94</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5656-4' platform='aix5.3' modified='2009-04-30'>
      <description>/var/adm/sulog file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #95</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5736-4' platform='aix5.3' modified='2009-04-30'>
      <description>/var/adm/utmp file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #96</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6062-4' platform='aix5.3' modified='2009-04-30'>
      <description>/var/adm/wtmp file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #97</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5453-6' platform='aix5.3' modified='2009-04-30'>
      <description>/var/adm/authlog file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #98</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6048-3' platform='aix5.3' modified='2009-04-30'>
      <description>/var/adm/syslog file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #99</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5832-1' platform='aix5.3' modified='2009-04-30'>
      <description>/var/mail file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #100</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6017-8' platform='aix5.3' modified='2009-04-30'>
      <description>/var/tmp file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #101</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5986-5' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/pt_chmod file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #103</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5875-0' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/embedded_us file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #104</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5977-4' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/sendmail file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #105</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5627-5' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/kerberos/bin/rsh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #107</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5455-1' platform='aix5.3' modified='2009-04-30'>
      <description>/var/spool/mail file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #108</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5077-3' platform='aix5.3' modified='2009-04-30'>
      <description>smbpassword file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #109</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5695-2' platform='aix5.3' modified='2009-04-30'>
      <description>At directory should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5646-5' platform='aix5.3' modified='2009-04-30'>
      <description>At directory should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5161-5' platform='aix5.3' modified='2009-04-30'>
      <description>at.allow file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5254-8' platform='aix5.3' modified='2009-04-30'>
      <description>at.allow file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5853-7' platform='aix5.3' modified='2009-04-30'>
      <description>at.deny file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5632-5' platform='aix5.3' modified='2009-04-30'>
      <description>at.deny file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5319-9' platform='aix5.3' modified='2009-04-30'>
      <description>Cron directories should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5412-2' platform='aix5.3' modified='2009-04-30'>
      <description>Cron directories should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5082-3' platform='aix5.3' modified='2009-04-30'>
      <description>Crontab directories should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5754-7' platform='aix5.3' modified='2009-04-30'>
      <description>Crontab directories should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6022-8' platform='aix5.3' modified='2009-04-30'>
      <description>cron.allow file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5868-5' platform='aix5.3' modified='2009-04-30'>
      <description>cron.allow file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5961-8' platform='aix5.3' modified='2009-04-30'>
      <description>cron.deny should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5837-0' platform='aix5.3' modified='2009-04-30'>
      <description>cron.deny data should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5929-5' platform='aix5.3' modified='2009-04-30'>
      <description>crontab files should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5085-6' platform='aix5.3' modified='2009-04-30'>
      <description>crontab files should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5919-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/resolv.conf file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5888-3' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/resolv.conf file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5941-0' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/named.boot file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5910-5' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/named.boot file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5822-2' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/named.conf file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5663-0' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/named.conf file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5086-4' platform='aix5.3' modified='2009-04-30'>
      <description>Each user home directory should be owned by an appropriate user.</description>
      <parameters>
        <parameter>user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6007-9' platform='aix5.3' modified='2009-04-30'>
      <description>Each user home directory should be owned by an appropriate group.</description>
      <parameters>
        <parameter>group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5088-0' platform='aix5.3' modified='2009-04-30'>
      <description>inetd.conf file should be owned by an appropriate user</description>
      <parameters>
        <parameter>user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5732-3' platform='aix5.3' modified='2009-04-30'>
      <description>inetd.conf file should be owned by an appropriate group</description>
      <parameters>
        <parameter>group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5326-4' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/exports should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5296-9' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/exports should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5283-7' platform='aix5.3' modified='2009-04-30'>
      <description>Exported files and directories should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5428-8' platform='aix5.3' modified='2009-04-30'>
      <description>Exported files and directories should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5626-7' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/services file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5957-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/services file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5740-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/notrouter file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #18</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5090-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/notrouter file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #18</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6086-3' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/samba/smb.conf file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6055-8' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/samba/smb.conf file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6024-4' platform='aix5.3' modified='2009-04-30'>
      <description>smbpasswd executable should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #22</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5839-6' platform='aix5.3' modified='2009-04-30'>
      <description>smbpasswd executable should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #22</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5091-4' platform='aix5.3' modified='2009-04-30'>
      <description>aliases file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5497-3' platform='aix5.3' modified='2009-04-30'>
      <description>aliases file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6029-3' platform='aix5.3' modified='2009-04-30'>
      <description>The log file configured to capture critical sendmail messages should be owned by the appropriate user.</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #25</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5116-9' platform='aix5.3' modified='2009-04-30'>
      <description>The log file configured to capture critical sendmail messages should be owned by the appropriate group.</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #25</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5154-0' platform='aix5.3' modified='2009-04-30'>
      <description>Programs executed through aliases file entries should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #26</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6013-7' platform='aix5.3' modified='2009-04-30'>
      <description>Programs executed through aliases file entries should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #26</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5999-8' platform='aix5.3' modified='2009-04-30'>
      <description>Shell files should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6003-8' platform='aix5.3' modified='2009-04-30'>
      <description>Shell files should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6096-2' platform='aix5.3' modified='2009-04-30'>
      <description>snmpd.conf file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #29</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6107-7' platform='aix5.3' modified='2009-04-30'>
      <description>snmpd.conf file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #29</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5171-4' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/syslog.conf file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #30</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5688-7' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/syslog.conf file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #30</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5185-4' platform='aix5.3' modified='2009-04-30'>
      <description>traceroute executable should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #31</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5671-3' platform='aix5.3' modified='2009-04-30'>
      <description>traceroute executable should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #31</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5706-7' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/sendmail file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #32</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6177-0' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/sendmail file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #32</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5860-2' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/passwd file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #35</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6146-5' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/passwd file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #35</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5992-3' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/shadow file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #36</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5615-0' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/shadow file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #36</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5580-6' platform='aix5.3' modified='2009-04-30'>
      <description>smbpasswd file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #37</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5191-2' platform='aix5.3' modified='2009-04-30'>
      <description>smbpasswd file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #37</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6088-9' platform='aix5.3' modified='2009-04-30'>
      <description>Environmental variable PATH for superuser accounts should or should not contain world-writable files as appropriate</description>
      <parameters>
        <parameter>should/should not</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
        <technical_mechanism>via profile</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6044-2' platform='aix5.3' modified='2009-04-30'>
      <description>Environmental variable PATH for superuser accounts should not contain the current directory as the first or last entry</description>
      <parameters>
        <parameter>should/should not</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via local init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5195-3' platform='aix5.3' modified='2009-04-30'>
      <description>The current working directory should or should not be added to the environmental variable PATH by global initialization files as appropriate</description>
      <parameters>
        <parameter>should/should not</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via local  init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #3</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6012-9' platform='aix5.3' modified='2009-04-30'>
      <description>The current working directory should or should not be added to the environmental variable PATH by local initialization files as appropriate</description>
      <parameters>
        <parameter>should/should not</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via local init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5361-1' platform='aix5.3' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5204-3' platform='aix5.3' modified='2009-04-30'>
      <description>The current working directory should or should not be added to the environmental variable PATH by run control scripts as appropriate</description>
      <parameters>
        <parameter>should/should not</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6087-1' platform='aix5.3' modified='2009-04-30'>
      <description>The system umask should be set appropriately</description>
      <parameters>
        <parameter>umask</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via global init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #8</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6056-6' platform='aix5.3' modified='2009-04-30'>
      <description>The user umask should be set appropriately</description>
      <parameters>
        <parameter>umask</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via local init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #8</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5816-4' platform='aix5.3' modified='2009-04-30'>
      <description>The cron.allow file should be configured with the set of users permitted to use the cron facility as appropriate.</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Text editor</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-5785-1' platform='aix5.3' modified='2009-04-30'>
      <description>The cron.deny file should be configured with the set of users not permitted to use the cron facility as appropriate.</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Text editor</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-5661-4' platform='aix5.3' modified='2009-04-30'>
      <description>Cron logging should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.3 4)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5877-6' platform='aix5.3' modified='2009-04-30'>
      <description>The at.allow file should be configured with the set of users permitted to use the at facility as appropriate.</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Text editor</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-5600-2' platform='aix5.3' modified='2009-04-30'>
      <description>The at.deny file should be configured with the set of users not permitted to use the at facility as appropriate.</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Text editor</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-5489-0' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/security/audit/config file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6066-5' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/security/audit/events file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6084-8' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/security/audit/objects file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #3</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5819-8' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/trcload file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5648-1' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/semutil file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5205-0' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/security/audit/config file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5548-3' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/security/audit/events file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6085-5' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/security/audit/objects file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #3</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5926-1' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/trcload file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5224-1' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/semutil file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6037-6' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/security/audit/config file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6011-1' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/security/audit/events file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5980-8' platform='aix5.3' modified='2009-04-30'>
      <description>/etc/security/audit/objects file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #3</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6103-6' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/trcload file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5945-1' platform='aix5.3' modified='2009-04-30'>
      <description>/usr/lib/semutil file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 1) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6079-8' platform='aix5.3' modified='2009-04-30'>
      <description>The authentication mechanism (SYSTEM attribute) should be set appropriately for each user</description>
      <parameters>
        <parameter>authentication system</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.1 2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6158-0' platform='aix5.3' modified='2009-04-30'>
      <description>Trusted Computing Base should be installed or not as appropriate</description>
      <parameters>
        <parameter>installed/not installed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.2 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5484-1' platform='aix5.3' modified='2009-04-30'>
      <description>Auditing should be enabled or disabled as appropriate in runcontrol scripts</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/inittab</technical_mechanism>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5378-5' platform='aix5.3' modified='2009-04-30'>
      <description>BIN mode auditing should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5235-7' platform='aix5.3' modified='2009-04-30'>
      <description>Accounts should be present or absent from the audit config file as appropriate</description>
      <parameters>
        <parameter>present/absent</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5913-9' platform='aix5.3' modified='2009-04-30'>
      <description>System logons should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5993-1' platform='aix5.3' modified='2009-04-30'>
      <description>System logoffs should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5693-7' platform='aix5.3' modified='2009-04-30'>
      <description>Password changes should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #3</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6230-7' platform='aix5.3' modified='2009-04-30'>
      <description>su usage should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5697-8' platform='aix5.3' modified='2009-04-30'>
      <description>Creation/modification of superuser groups should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6197-8' platform='aix5.3' modified='2009-04-30'>
      <description>Startup/shutdown of audit functions should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5889-1' platform='aix5.3' modified='2009-04-30'>
      <description>Certificate revocation should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6109-3' platform='aix5.3' modified='2009-04-30'>
      <description>Remote access from outside the corporate network should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5242-3' platform='aix5.3' modified='2009-04-30'>
      <description>Use of chown command should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6213-3' platform='aix5.3' modified='2009-04-30'>
      <description>File permissions of the rcp binary should be set correctly</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.4 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5680-4' platform='aix5.3' modified='2009-04-30'>
      <description>File permissions of the rlogin binary should be set correctly</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.4 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5591-3' platform='aix5.3' modified='2009-04-30'>
      <description>File permissions of the rlogind binary should be set correctly</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.4 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5543-4' platform='aix5.3' modified='2009-04-30'>
      <description>File permissions of the rsh binary should be set correctly</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.4 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5934-5' platform='aix5.3' modified='2009-04-30'>
      <description>File permissions of the rshd binary should be set correctly</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.4 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6009-5' platform='aix5.3' modified='2009-04-30'>
      <description>File permissions of the tftp binary should be set correctly</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.4 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5996-4' platform='aix5.3' modified='2009-04-30'>
      <description>File permissions of the tftpd binary should be set correctly</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.4 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6135-8' platform='aix5.3' modified='2009-04-30'>
      <description>Global initialization files should allow or deny write access to the terminal as appropriate</description>
      <parameters>
        <parameter>allow/deny</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via global init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.5 1) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5963-4' platform='aix5.3' modified='2009-04-30'>
      <description>Netrc should be configured with an appropriate set of services</description>
      <parameters>
        <parameter>list of services</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/sysck.cfg</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.4 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6104-4' platform='aix5.3' modified='2009-04-30'>
      <description>Change of file ownership should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5324-9' platform='aix5.3' modified='2009-04-30'>
      <description>Use of chmod command should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6170-5' platform='aix5.3' modified='2009-04-30'>
      <description>Certificate creation should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5243-1' platform='aix5.3' modified='2009-04-30'>
      <description>Certificate deletion should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6016-0' platform='aix5.3' modified='2009-04-30'>
      <description>Certificate retrieval should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6174-7' platform='aix5.3' modified='2009-04-30'>
      <description>Startup or shutdown of the audit process should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5245-6' platform='aix5.3' modified='2009-04-30'>
      <description>Use of chgrp should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5253-0' platform='aix5.3' modified='2009-04-30'>
      <description>Use of mkgroup should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6189-5' platform='aix5.3' modified='2009-04-30'>
      <description>Use of rmgroup should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6035-0' platform='aix5.3' modified='2009-04-30'>
      <description>Use of change user functions should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6100-2' platform='aix5.3' modified='2009-04-30'>
      <description>Terminal logoffs should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6157-2' platform='aix5.3' modified='2009-04-30'>
      <description>Exit function usage should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/audit/config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-5 E.3 4) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6156-4' platform='aix5.3' modified='2009-04-30'>
      <description>Hard core dump size limits should be set appropriately</description>
      <parameters>
        <parameter>Size (0 to disable core dumps)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/limits ulimit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.4 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5751-3' platform='aix5.3' modified='2009-04-30'>
      <description>Remote root logins via SSH should be allowed or not as appropriate.</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/ssh/sshd_config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (4)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27905-9' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>Apache's configuration directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27713-7' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>Apache's configuration directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27582-6' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>Apache's demo CGI printenv.pl should be available or removed as appropriate</description>
      <parameters>
        <parameter>(1) exist / not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) (ServerRoot)\cgi-bin\printenv.pl</technical_mechanism>
        <technical_mechanism>(2) (ServerRoot)/cgi-bin/printenv.pl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 18. Remove Default/Unneeded Apache Files p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.18 Remove Default Content p33</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27923-2' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>testcgi should be installed as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) cgi-script directory</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 18. Remove Default/Unneeded Apache Files p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.18 Remove Default Content p33</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27885-3' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The "FollowSymLinks" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) FollowSymLinks / -FollowSymLinks / +FollowSymLinks / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p23</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27991-9' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The "IncludesNOEXEC" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) IncludesNoExec / -IncludesNoExec / +IncludesNoExec / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27484-5' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The "Indexes" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) Indexes / -Indexes / +Indexes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27784-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Allow Directive for the OS root should be configured appropriately</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Allow directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 13. Access Control Directives p21</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p14-15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27505-7' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Allow directive for the specified Directory directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Allow directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 13. Access Control Directives p21</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p14-15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27969-5' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "KeepAlive" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) On / Off</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: KeepAlive directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 10. Denial of Service (DoS) Protective General Directives pg 16</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27797-0' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "KeepAliveTimeout" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in seconds)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: KeepAliveTimeout directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 10. Denial of Service (DoS) Protective General Directives pg 16</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28018-0' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "LimitRequestBody" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in bytes)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestBody directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L2 7. Buffer Overflow Protections p42</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.14 Buffer Overflow Protection Tuning p23</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27962-0' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "LimitRequestFields" directive should be configured appropriately</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestFields directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L2 7. Buffer Overflow Protections p42</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.14 Buffer Overflow Protection Tuning p24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27025-6' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "LimitRequestFieldSizeBody" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in bytes)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestFieldSizeBody directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L2 7. Buffer Overflow Protections p42</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.14 Buffer Overflow Protection Tuning p24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28008-1' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "LimitRequestline" directive should be configured appropriatley.</description>
      <parameters>
        <parameter>(1) Number value (in bytes)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestLine directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L2 7. Buffer Overflow Protections p42</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.14 Buffer Overflow Protection Tuning p24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27805-1' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "LogLevel" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) debug / info / notice / warn / error / crit / alert / emerg</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LogLevel directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 17. Logging General Directives p26</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.17 Logging p31</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27264-1' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "MaxClients" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MaxClients directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 10. Denial of Service (DoS) Protective General Directives pg 16</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p22</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27863-0' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "ServerTokens" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Prod[uctOnly] / Major / Minor / Min[imal] / OS / Full</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ServerTokens directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.16 Software Information Leakage Protection p29</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27790-5' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "Timeout" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in seconds)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Timeout directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 10. Denial of Service (DoS) Protective General Directives pg 16</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27855-6' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache access log file data should be configured to contain the appropriate data elements.</description>
      <parameters>
        <parameter>(1) LogFormat Format String</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LogFormat directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 17. Logging General Directives p26</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.17 Logging p30</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27823-4' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache AllowOverride Directive should be configured appropriately for operating system root directories.</description>
      <parameters>
        <parameter>(1) AuthConfig / FileInfo / Indexes / Limit / Options / All / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: AllowOverride directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27701-2' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache AllowOverride directive should be configured appropriately for web site root directories.</description>
      <parameters>
        <parameter>(1) AuthConfig / FileInfo / Indexes / Limit / Options / All / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: AllowOverride directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27960-4' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache ErrorDocument directive should be set correctly for HTTP 400 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 400' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27939-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache Group directive should be set correctly.</description>
      <parameters>
        <parameter>(1) group name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Group directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 8. User Oriented General Directives p14</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.6 Creating the Apache User and Group Accounts p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27324-3' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache runtime rewriting engine should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) off/on</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: RewriteEngine directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 21. Deny HTTP TRACE Requests with Mod_Rewrite p33</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.11 Restrict HTTP Protocol Version p19</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27896-0' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache ServerSignature directive should be set appropriately.</description>
      <parameters>
        <parameter>(1) On/Off/EMail</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ServerSignature directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.16 Software Information Leakage Protection p29</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27739-2' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache system logging should be configured appropriately.</description>
      <parameters>
        <parameter>(1) File path | pipe</parameter>
        <parameter>(2)  LogFormat | nickname</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: CustomLog directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 17. Logging General Directives p26</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.17 Logging p31</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27983-6' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache user account should be allowed root privileges as appropriate.</description>
      <parameters>
        <parameter>(1) allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 4. Create the Apache Web User Account p11</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.6 Creating the Apache User and Group Accounts p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27942-2' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache User directive should be set correctly.</description>
      <parameters>
        <parameter>(1) user name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: User directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 8. User Oriented General Directives p13</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.6 Creating the Apache User and Group Accounts p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27029-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 401 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 401' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27867-1' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 403 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 403' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27951-3' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 404 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 404' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27963-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 405 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 405' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28026-3' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 500 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 500' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27321-9' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Deny Directive for the OS root should be configured appropriately</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Deny directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 13. Access Control Directives p21</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p14-15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27592-5' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Deny directive for the specified Directory directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Deny directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 13. Access Control Directives p21</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p14-15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27755-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The group membership of any Apache files in /var/log/httpd/ should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27958-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The group membership of the Apache /etc/httpd/conf.d file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27804-4' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The group membership of the Apache /etc/httpd/conf/passwd file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27988-5' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The group membership of the Apache /usr/sbin/apachectl file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27832-5' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The group membership of the Apache /usr/sbin/httpd file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27770-7' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The group membership of the Apache /var/www/html file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27475-3' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The group membership of the Apache user account should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/group</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 4. Create the Apache Web User Account p11</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.6 Creating the Apache User and Group Accounts p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28028-9' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ownership of log files in Apache /var/log/httpd/ should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27970-3' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ownership of the Apache /etc/httpd/conf.d file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27036-3' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ownership of the Apache /etc/httpd/conf/passwd file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27136-1' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ownership of the Apache /usr/sbin/apachectl file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27932-3' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ownership of the Apache /usr/sbin/httpd file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27561-0' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The ownership of the Apache /var/www/html file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28004-0' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The path for Apache sites error log files should be configured appropriately.</description>
      <parameters>
        <parameter>(1) File path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ErrorLog directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L2 4. ErrorLog - Syslog p70-71</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.5 Syslog Logging p44-45</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27956-2' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The permissions for the Apache /etc/httpd/conf.d file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27929-9' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The permissions for the Apache /etc/httpd/conf/passwd file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27632-9' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The permissions for the Apache /usr/sbin/apachectl file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27902-6' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The permissions for the Apache /usr/sbin/httpd file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27997-6' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The permissions for the Apache/var/www/html file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27537-0' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The permissions of any Apache files in /var/log/httpd/ should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28019-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Unix permissions of Apache's configuration directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27874-7' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The"Includes" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) Includes / -Includes / +Includes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27656-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The"MultiViews" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) MultiViews / -MultiViews / +MultiViews / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24-25</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27071-0' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Order directive for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Allow,Deny / Deny,Allow / Mutual-failure</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Order directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 13. Access Control Directives p21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27987-7' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>Permitted HTTP request methods should be configured appropriately.</description>
      <parameters>
        <parameter>(1) methods</parameter>
        <parameter>(2) access control directives</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitExecpt directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 16. Limiting HTTP Request Methods p25</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27489-4' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>Access to Apache's httpd.conf file should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by (ServerRoot)\conf\httpd.conf's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28009-9' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Windows permissions for all files specified by CustomLog directives should be configured appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27977-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Windows permissions for all files specified by ErrorLog directives should be configured appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27802-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The location of the Apache htpasswd file should be set correctly.</description>
      <parameters>
        <parameter>(1) directory path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Directory of htpasswd file</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 14. Authentication Mechanisms p22</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27803-6' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache Server Administrator email address should be set correctly.</description>
      <parameters>
        <parameter>(1) email address</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) 'ServerAdmin' line in Apache configuration file</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 8. User Oriented General Directives p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27924-0' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache user account should be locked or unlocked as appropriate.</description>
      <parameters>
        <parameter>(1) locked/unlocked</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 5. Lock Down the Apache Web User Account p11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28027-1' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>File permissions for httpd.conf should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27147-8' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The httpd.conf file should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28109-7' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The httpd.conf file should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27949-7' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Unix permissions of Apache's htpasswd file should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27502-4' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The htpasswd should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28001-6' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The htpasswd file should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28139-4' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "StartServers" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: StartServers directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p22</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27654-3' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "MinSpareServers" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MinSpareServers directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p22</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27916-6' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Apache "MaxSpareServers" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MaxSpareServers directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p22</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27785-5' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The "ExecCGI" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) ExecCGI / -ExecCGI/ +ExecCGI / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28125-3' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Order directive for all DocumentRoot directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Allow,Deny / Deny,Allow / Mutual-failure</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Order directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28116-2' platform='apache-httpd1.3' modified='2013-02-11'>
      <description>The Order directive for the specified Directory directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Allow,Deny / Deny,Allow / Mutual-failure</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) TARGET: Directory directive</technical_mechanism>
        <technical_mechanism>(2) Apache configuration file: Order directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28025-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache Action directive shoud be configured appropriately.</description>
      <parameters>
        <parameter>(1) action-type</parameter>
        <parameter>(2) cgi-script</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Action directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: MIME types for csh or sh shell programs must be disabled.
STIG ID: WG370 A22 Rule ID: SV-36309r1_rule Vuln ID: V-2225
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28092-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache AddHandler directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) handler-name</parameter>
        <parameter>(2) extension</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: AddHandler directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: MIME types for csh or sh shell programs must be disabled.
STIG ID: WG370 A22 Rule ID: SV-36309r1_rule Vuln ID: V-2225
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28000-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Anonymous sharing of Apache's web content directories with nfs should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Set of shares</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/exports</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web content directories must not be anonymously shared.
STIG ID: WG210 A22  Rule ID: SV-33022r1_rule  Vuln ID: V-2226
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27251-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Anonymous sharing of Apache's web content directories with smb should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Set of shares</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/samba/smb.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web content directories must not be anonymously shared.
STIG ID: WG210 A22  Rule ID: SV-33022r1_rule  Vuln ID: V-2226
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28090-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache AllowOverride directive should be configured appropriately for web site root directories.</description>
      <parameters>
        <parameter>(1) AuthConfig / FileInfo / Indexes / Limit / Options / All / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: AllowOverride directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All interactive programs must be placed in a designated directory with appropriate permissions.
STIG ID: WG400 A22  Rule ID: SV-6928r4_rule  Vuln ID: V-2228
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All interactive programs must be placed in a designated directory with appropriate permissions.
STIG ID: WG400 W22  Rule ID: SV-36644r1_rule  Vuln ID: V-2228
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27660-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apachce "MaxKeepAliveRequests" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MaxKeepAliveRequests directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The number of allowed simultaneous requests must be set.
STIG ID: WG110 A22  Rule ID: SV-33018r1_rule  Vuln ID: V-2240
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The number of allowed simultaneous requests must be set.
STIG ID: WG110 W22  Rule ID: SV-33105r1_rule  Vuln ID: V-2240
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28122-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All readable Apache web document directories should have their default webpage configured appropriately.</description>
      <parameters>
        <parameter>(1) exist / not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Directories (from Apache configuration file: DocumentRoot directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Each readable web document directory must contain either a default, home, index, or equivalent file.
STIG ID: WG170 A22  Rule ID: SV-33020r1_rule  Vuln ID: V-2245
Severity: CAT III  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Each readable web document directory must contain either a default, home, index, or equivalent file.
STIG ID: WG170 W22  Rule ID: SV-33107r1_rule  Vuln ID: V-2245
Severity: CAT III  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27490-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>File permissions for httpd.conf should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web administration tools must be restricted to the web manager and the web manager’s designees.
STIG ID: WG220 A22  Rule ID: SV-32948r1_rule  Vuln ID: V-2248
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28118-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The httpd.conf file should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web administration tools must be restricted to the web manager and the web manager’s designees.
STIG ID: WG220 A22  Rule ID: SV-32948r1_rule  Vuln ID: V-2248
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27952-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The httpd.conf file should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web administration tools must be restricted to the web manager and the web manager’s designees.
STIG ID: WG220 A22  Rule ID: SV-32948r1_rule  Vuln ID: V-2248
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27955-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's log_config_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) log_config_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Logs of web server access and errors must be established and maintained.
STIG ID: WG240 A22  Rule ID: SV-33025r1_rule  Vuln ID: V-2250
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Logs of web server access and errors must be established and maintained.
STIG ID: WG240 W20  Rule ID: SV-36668r1_rule  Vuln ID: V-2250
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27967-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The file permissions for all files specified by CustomLog directives should be configured appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27906-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All files specified by CustomLog directives should be owned by the appropriate user</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27976-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All files specified by CustomLog directives should be owned by the appropriate group</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28059-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions for all files specified by ErrorLog directives should be configured appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27888-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All files specified by ErrorLog directives should be owned by the appropriate user</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27889-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All files specified by ErrorLog directives should be owned by the appropriate group</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27795-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions of Apache's htpasswd file should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server’s htpasswd files (if present) must reflect proper ownership and permissions.
STIG ID: WG270 A22  Rule ID: SV-36478r1_rule  Vuln ID: V-2255
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28071-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The htpasswd should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server’s htpasswd files (if present) must reflect proper ownership and permissions.
STIG ID: WG270 A22  Rule ID: SV-36478r1_rule  Vuln ID: V-2255
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27981-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The htpasswd file should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server’s htpasswd files (if present) must reflect proper ownership and permissions.
STIG ID: WG270 A22  Rule ID: SV-36478r1_rule  Vuln ID: V-2255
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28013-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions for all directories specified by ScriptAlias directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28141-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All directories specified by ScriptAlias directives should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28020-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All directories specified by ScriptAlias directives should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28084-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions for all directories specified by ScriptAliasMatch directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27611-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All directories specified by ScriptAliasMatch directives should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28146-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All directories specified by ScriptAliasMatch directives should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27811-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions for all directories specified by DocumentRoot directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28107-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All directories specified by DocumentRoot directives should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27499-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All directories specified by DocumentRoot directives should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27620-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions for all directories specified by Alias directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27933-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All directories specified by Alias directives should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28117-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All directories specified by Alias directives should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27957-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions for all directories specified by ServerRoot directives should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27871-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All directories specified by ServerRoot directives should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27647-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All directories specified by ServerRoot directives should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28055-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions of Apache's configuration directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28119-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's configuration directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28069-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's configuration directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28006-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions of Apache's /bin directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27742-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's /bin directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27914-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's /bin directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28046-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions of Apache's /logs directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28126-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's /logs directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27979-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's /logs directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27643-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions of Apache's /htdocs directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28035-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's /htdocs directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27984-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's /htdocs directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28115-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Unix permissions of Apache's /cgi-bin directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28068-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's /cgi-bin directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28030-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's /cgi-bin directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28044-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache site's robots.txt should be configured to disallow paths and files as appropriate.</description>
      <parameters>
        <parameter>(1) User-Agent</parameter>
        <parameter>(2) Disallowed path(s)|file(s)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) robots.txt</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must not respond to requests from public search engines.
STIG ID: WG310 A22  Rule ID: SV-33028r1_rule  Vuln ID: V-2260
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must not respond to requests from public search engines.
STIG ID: WG310 W22  Rule ID: SV-28798r2_rule  Vuln ID: V-2260
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28137-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's ssl_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) ssl_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 A22  Rule ID: SV-33029r1_rule  Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 W20  Rule ID: SV-36740r1_rule  Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28104-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache SSLProtocol directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) SSLv2 / SSLv3 / TLSv1 / All</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: SSLProtocol directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 A22  Rule ID: SV-33029r1_rule  Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 W20  Rule ID: SV-36740r1_rule  Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27980-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache SSLEngine directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) On / Off</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: SSLEngine directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 A22  Rule ID: SV-33029r1_rule  Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 W20  Rule ID: SV-36740r1_rule  Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27821-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "ServerTokens" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Prod[uctOnly] / Major / Minor / Min[imal] / OS / Full</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ServerTokens directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server and/or operating system information must be protected.
STIG ID: WG520 A22  Rule ID: SV-36672r1_rule  Vuln ID: V-6724
Severity: CAT III  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server and/or operating system information must be protected.
STIG ID: WG520 W22  Rule ID: SV-33098r1_rule  Vuln ID: V-6724
Severity: CAT III  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27835-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>All Apache's online manual should be available or removed as appropriate.</description>
      <parameters>
        <parameter>(1) exist / not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) manual in the Server Root directory</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All web server documentation, sample code, example applications, and tutorials must be  removed from a production web server.
STIG ID: WG385 A22  Rule ID: SV-32933r1_rule  Vuln ID: V-13621
Severity: CAT I  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All web server documentation, sample code, example applications, and tutorials must be  removed from a production web server.
STIG ID: WG385 W22  Rule ID: SV-33087r1_rule  Vuln ID: V-13621
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28034-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's demo CGI printenv.pl should be available or removed as appropriate</description>
      <parameters>
        <parameter>(1) exist / not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) (ServerRoot)\cgi-bin\printenv.pl</technical_mechanism>
        <technical_mechanism>(2) (ServerRoot)/cgi-bin/printenv.pl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 18. Remove Default/Unneeded Apache Files p27</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All web server documentation, sample code, example applications, and tutorials must be  removed from a production web server.
STIG ID: WG385 A22  Rule ID: SV-32933r1_rule  Vuln ID: V-13621
Severity: CAT I  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All web server documentation, sample code, example applications, and tutorials must be  removed from a production web server.
STIG ID: WG385 W22  Rule ID: SV-33087r1_rule  Vuln ID: V-13621
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28010-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache access log file data should be configured to contain the appropriate data elements.</description>
      <parameters>
        <parameter>(1) LogFormat Format String</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LogFormat directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 17. Logging General Directives p26</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file data must contain required data elements.
STIG ID: WG242 A22  Rule ID: SV-36642r1_rule  Vuln ID: V-13688
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file data must contain required data elements.
STIG ID: WG242 W22  Rule ID: SV-28654r2_rule  Vuln ID: V-13688
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28143-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "Timeout" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in seconds)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Timeout directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 10. Denial of Service (DoS) Protective General Directives pg 16</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The Timeout directive must be properly set.
STIG ID: WA000-WWA020 A22  Rule ID: SV-32977r1_rule  Vuln ID: V-13724
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The Timeout directive must be properly set.
STIG ID: WA000-WWA020 W22  Rule ID: SV-32980r1_rule  Vuln ID: V-13724
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27148-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "KeepAlive" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) On / Off</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: KeepAlive directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 10. Denial of Service (DoS) Protective General Directives pg 16</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The KeepAlive directive must be enabled.
STIG ID: WA000-WWA022 A22  Rule ID: SV-32844r1_rule  Vuln ID: V-13725
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The KeepAlive directive must be enabled.
STIG ID: WA000-WWA022 W22  Rule ID: SV-32987r1_rule  Vuln ID: V-13725
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27938-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "KeepAliveTimeout" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in seconds)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: KeepAliveTimeout directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 10. Denial of Service (DoS) Protective General Directives pg 16</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The KeepAliveTimeout directive must be defined.
STIG ID: WA000-WWA024 A22  Rule ID: SV-32877r1_rule  Vuln ID: V-13726
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The KeepAliveTimeout directive must be defined.
STIG ID: WA000-WWA024 W22  Rule ID: SV-32880r1_rule  Vuln ID: V-13726
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27479-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "StartServers" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: StartServers directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The httpd.conf StartServers directive must be set properly.
STIG ID: WA000-WWA026 A22  Rule ID: SV-36645r1_rule  Vuln ID: V-13727
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27989-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "MinSpareServers" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MinSpareServers directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The httpd.conf MinSpareServers directive must be set properly. 
STIG ID: WA000-WWA028 A22  Rule ID: SV-36646r1_rule  Vuln ID: V-13728
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28133-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "MaxSpareServers" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MaxSpareServers directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The httpd.conf MaxSpareServers directive must be set properly. 
STIG ID: WA000-WWA030 A22  Rule ID: SV-36648r1_rule  Vuln ID: V-13729
Severity: CAT III  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27188-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "MaxClients" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MaxClients directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 10. Denial of Service (DoS) Protective General Directives pg 16</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The httpd.conf MaxClients directive must be set properly. 
STIG ID: WA000-WWA032 A22  Rule ID: SV-36649r1_rule  Vuln ID: V-13730
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28066-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "FollowSymLinks" setting for all "Options" directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) FollowSymLinks / -FollowSymLinks / +FollowSymLinks / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The FollowSymLinks setting must be disabled.
STIG ID: WA000-WWA052 A22  Rule ID: SV-40129r1_rule  Vuln ID: V-13732
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28183-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "Includes" setting for all "Options" directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Includes / -Includes / +Includes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Server side includes (SSIs) must run with execution capability disabled.
STIG ID: WA000-WWA054 A22  Rule ID: SV-32753r1_rule  Vuln ID: V-13733
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28101-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "IncludesNoExec" setting for all "Options" directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) IncludesNoExec / -IncludesNoExec / +IncludesNoExec / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Server side includes (SSIs) must run with execution capability disabled.
STIG ID: WA000-WWA054 A22  Rule ID: SV-32753r1_rule  Vuln ID: V-13733
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28100-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "MultiViews" setting for all "Options" directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) MultiViews / -MultiViews / +MultiViews / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The MultiViews directive must be disabled.
STIG ID: WA000-WWA056 A22  Rule ID: SV-32754r1_rule  Vuln ID: V-13734
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27737-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "Indexes" setting for all "Options" directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Indexes / -Indexes / +Indexes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Directory indexing must be disabled on directories not containing index files.
STIG ID: WA000-WWA058 A22  Rule ID: SV-32755r1_rule  Vuln ID: V-13735
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28089-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "LimitRequestBody" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in bytes)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestBody directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L2 7. Buffer Overflow Protections p42</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request message body size must be limited.
STIG ID: WA000-WWA060 A22  Rule ID: SV-32756r1_rule  Vuln ID: V-13736
Severity: CAT II  Class: Unclass+G66</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request message body size must be limited.
STIG ID: WA000-WWA060 W22  Rule ID: SV-33008r1_rule  Vuln ID: V-13736
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27646-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "LimitRequestFields" directive should be configured appropriately</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestFields directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L2 7. Buffer Overflow Protections p42</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request header fields must be limited.
STIG ID: WA000-WWA062 A22  Rule ID: SV-32757r1_rule  Vuln ID: V-13737
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request header fields must be limited.
STIG ID: WA000-WWA062 W22  Rule ID: SV-33009r1_rule  Vuln ID: V-13737
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27907-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "LimitRequestFieldSizeBody" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in bytes)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestFieldSizeBody directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L2 7. Buffer Overflow Protections p42</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request header field size must be limited.
STIG ID: WA000-WWA064 A22  Rule ID: SV-32766r1_rule  Vuln ID: V-13738
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request header field size must be limited.
STIG ID: WA000-WWA064 W22  Rule ID: SV-33010r1_rule  Vuln ID: V-13738
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28106-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "LimitRequestline" directive should be configured appropriatley.</description>
      <parameters>
        <parameter>(1) Number value (in bytes)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestLine directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L2 7. Buffer Overflow Protections p42</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request line must be limited.
STIG ID: WA000-WWA066 A22  Rule ID: SV-32768r1_rule  Vuln ID: V-13739
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request line must be limited.
STIG ID: WA000-WWA066 W22  Rule ID: SV-33011r1_rule  Vuln ID: V-13739
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27847-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The path for Apache sites error log files should be configured appropriately.</description>
      <parameters>
        <parameter>(1) File path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ErrorLog directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L2 4. ErrorLog - Syslog p70-71</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Error logging must be enabled.
STIG ID: WA00605 A22  Rule ID: SV-33192r1_rule  Vuln ID: V-26279
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Error logging must be enabled.
STIG ID: WA00605 W22  Rule ID: SV-33147r1_rule  Vuln ID: V-26279
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27798-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache system logging should be configured appropriately.</description>
      <parameters>
        <parameter>(1) File path | pipe</parameter>
        <parameter>(2)  LogFormat | nickname</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: CustomLog directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 17. Logging General Directives p26</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: System logging must be enabled.
STIG ID: WA00615 A22  Rule ID: SV-33206r1_rule  Vuln ID: V-26281
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: System logging must be enabled.
STIG ID: WA00615 W22  Rule ID: SV-33151r1_rule  Vuln ID: V-26281
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27814-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "LogLevel" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) debug / info / notice / warn / error / crit / alert / emerg</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LogLevel directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 17. Logging General Directives p26</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The LogLevel directive must be enabled.
STIG ID: WA00620 A22  Rule ID: SV-33207r1_rule  Vuln ID: V-26282
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The LogLevel directive must be enabled.
STIG ID: WA00620 W22  Rule ID: SV-33153r1_rule  Vuln ID: V-26282
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27207-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Web Distributed Authoring and Versioning (WebDav) dav_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) dav_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web Distributed Authoring and Versioning (WebDAV) must be disabled.
STIG ID: WA00505 A22  Rule ID: SV-33216r1_rule  Vuln ID: V-26287
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web Distributed Authoring and Versioning (WebDAV) must be disabled.
STIG ID: WA00505 W20  Rule ID: SV-36611r1_rule  Vuln ID: V-26287
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27946-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Web Distributed Authoring and Versioning (WebDav) dav_fs_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) dav_fs_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web Distributed Authoring and Versioning (WebDAV) must be disabled.
STIG ID: WA00505 A22  Rule ID: SV-33216r1_rule  Vuln ID: V-26287
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web Distributed Authoring and Versioning (WebDAV) must be disabled.
STIG ID: WA00505 W20  Rule ID: SV-36611r1_rule  Vuln ID: V-26287
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28200-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's info_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) info_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server status module will be disabled.
STIG ID: WA00510 A22  Rule ID: SV-33218r1_rule  Vuln ID: V-26294
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server status module will be disabled.
STIG ID: WA00510 W20  Rule ID: SV-36612r1_rule  Vuln ID: V-26294
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27789-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's status_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) status_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server status module will be disabled.
STIG ID: WA00510 A22  Rule ID: SV-33218r1_rule  Vuln ID: V-26294
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server status module will be disabled.
STIG ID: WA00510 W20  Rule ID: SV-36612r1_rule  Vuln ID: V-26294
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28182-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's proxy_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) proxy_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 A22  Rule ID: SV-33220r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 W20  Rule ID: SV-36613r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28075-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's proxy_ftp_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) proxy_ftp_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 A22  Rule ID: SV-33220r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 W20  Rule ID: SV-36613r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27846-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's proxy_http_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) proxy_http_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 A22  Rule ID: SV-33220r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 W20  Rule ID: SV-36613r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28067-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's proxy_connect_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) proxy_connect_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 A22  Rule ID: SV-33220r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 W20  Rule ID: SV-36613r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27827-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>User-specific directories should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) userdir_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: User specific directories must not be globally enabled.
STIG ID: WA00525 A22  Rule ID: SV-33221r1_rule  Vuln ID: V-26302
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: User specific directories must not be globally enabled.
STIG ID: WA00525 W20  Rule ID: SV-36614r1_rule  Vuln ID: V-26302
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28120-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's process ID (PID) file's Unix permissions should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The process ID (PID) file must be properly secured.
STIG ID: WA00530 A22  Rule ID: SV-33222r1_rule  Vuln ID: V-26305
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28038-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's process ID (PID) file should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The process ID (PID) file must be properly secured.
STIG ID: WA00530 A22  Rule ID: SV-33222r1_rule  Vuln ID: V-26305
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27670-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's process ID (PID) file should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The process ID (PID) file must be properly secured.
STIG ID: WA00530 A22  Rule ID: SV-33222r1_rule  Vuln ID: V-26305
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27999-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's Scoreboard file's Unix permissions should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ScoreBoard file must be properly secured.
STIG ID: WA00535 A22  Rule ID: SV-33223r1_rule  Vuln ID: V-26322
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27715-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's scoreboard file should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ScoreBoard file must be properly secured.
STIG ID: WA00535 A22  Rule ID: SV-33223r1_rule  Vuln ID: V-26322
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27606-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's scoreboard (PID) file should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ScoreBoard file must be properly secured.
STIG ID: WA00535 A22  Rule ID: SV-33223r1_rule  Vuln ID: V-26322
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28102-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Order directive for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Allow,Deny / Deny,Allow / Mutual-failure</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Order directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 13. Access Control Directives p21</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 A22  Rule ID: SV-33226r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 W22  Rule ID: SV-33180r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27572-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Allow Directive for the OS root should be configured appropriately</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Allow directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 13. Access Control Directives p21</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 A22  Rule ID: SV-33226r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 W22  Rule ID: SV-33180r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27853-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Deny Directive for the OS root should be configured appropriately</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Deny directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 13. Access Control Directives p21</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 A22  Rule ID: SV-33226r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 W22  Rule ID: SV-33180r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27982-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "ExecCGI" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) ExecCGI / -ExecCGI/ +ExecCGI / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28113-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "FollowSymLinks" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) FollowSymLinks / -FollowSymLinks / +FollowSymLinks / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28064-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "Includes" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Includes / -Includes / +Includes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28037-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "IncludesNoExec" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) IncludesNoExec / -IncludesNoExec / +IncludesNoExec / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27762-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "Indexes" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Indexes / -Indexes / +Indexes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28206-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "MultiViews" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) MultiViews / -MultiViews / +MultiViews / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27769-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "SymLinksIfOwnerMatch" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) SymLinksIfOwnerMatch / -SymLinksIfOwnerMatch / +SymLinksIfOwnerMatch / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27748-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache "TraceEnable" directive should be configured appropriatley.</description>
      <parameters>
        <parameter>(1) on / off / extended</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: TraceEnable directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The TRACE method must be disabled.
STIG ID: WA00550 A22  Rule ID: SV-33227r1_rule  Vuln ID: V-26325
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The TRACE method must be disabled.
STIG ID: WA00550 W22  Rule ID: SV-33183r1_rule  Vuln ID: V-26325
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28152-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's listening IP address should be configured appropriately.</description>
      <parameters>
        <parameter>(1) IP-address</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Listen directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to listen on a specific IP address and port.
STIG ID: WA00555 A22  Rule ID: SV-33228r1_rule  Vuln ID: V-26326
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to listen on a specific IP address and port.
STIG ID: WA00555 W22  Rule ID: SV-33184r1_rule  Vuln ID: V-26326
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27419-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's listening port should be configured appropriately.</description>
      <parameters>
        <parameter>(1) port number</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Listen directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to listen on a specific IP address and port.
STIG ID: WA00555 A22  Rule ID: SV-33228r1_rule  Vuln ID: V-26326
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to listen on a specific IP address and port.
STIG ID: WA00555 W22  Rule ID: SV-33184r1_rule  Vuln ID: V-26326
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28163-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ScriptAlias for the specified directory should be configured appropriately.</description>
      <parameters>
        <parameter>(1) url-path</parameter>
        <parameter>(2) TARGET: directory path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ScriptAlias directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The URL-path name must be set to the file path name or the directory path name.
STIG ID: WA00560 A22  Rule ID: SV-33229r1_rule  Vuln ID: V-26327
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The URL-path name must be set to the file path name or the directory path name.
STIG ID: WA00560 W22  Rule ID: SV-33185r1_rule  Vuln ID: V-26327
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28111-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Automatic directory indexing should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) autoindex_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Automatic directory indexing must be disabled.
STIG ID: WA00515 A22  Rule ID: SV-33219r1_rule  Vuln ID: V-26368
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Automatic directory indexing must be disabled.
STIG ID: WA00515 W20  Rule ID: SV-36620r1_rule  Vuln ID: V-26368
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28070-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache AllowOverride Directive should be configured appropriately for operating system root directories.</description>
      <parameters>
        <parameter>(1) AuthConfig / FileInfo / Indexes / Limit / Options / All / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: AllowOverride directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ability to override the access configuration for the OS root directory must be disabled.
STIG ID: WA00547 A22  Rule ID: SV-33232r1_rule  Vuln ID: V-26393
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ability to override the access configuration for the OS root directory must be disabled.
STIG ID: WA00547 W22  Rule ID: SV-33237r1_rule  Vuln ID: V-26393
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28091-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Permitted HTTP request methods should be configured appropriately.</description>
      <parameters>
        <parameter>(1) methods</parameter>
        <parameter>(2) access control directives</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitExecpt directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 16. Limiting HTTP Request Methods p25</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: HTTP request methods must be limited.
STIG ID: WA00565 A22  Rule ID: SV-33236r1_rule  Vuln ID: V-26396
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: HTTP request methods must be limited.
STIG ID: WA00565 W22  Rule ID: SV-33238r1_rule  Vuln ID: V-26396
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28033-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Anonymous sharing of Apache's web content directories should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Set of shares</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\NullSessionShares </technical_mechanism>
        <technical_mechanism>(2) defined by Local or Group Policy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web content directories must not be anonymously shared.
STIG ID: WG210 W22  Rule ID: SV-33109r1_rule  Vuln ID: V-2226
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28007-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The maximum password age setting for Apache's service account should be configured appropriately.</description>
      <parameters>
        <parameter>(1) number of days</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by Local or Group Policy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The service account used to run the web service must have its password changed at least    annually.
STIG ID: WG060 W22  Rule ID: SV-36489r1_rule  Vuln ID: V-2235
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27628-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Access to Apache's httpd.conf file should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by (ServerRoot)\conf\httpd.conf's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web administration tools must be restricted to the web manager and the web manager’s designees.
STIG ID: WG220 W22  Rule ID: SV-33072r1_rule  Vuln ID: V-2248
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27412-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions for all files specified by CustomLog directives should be configured appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 W22  Rule ID: SV-33135r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28042-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions for all files specified by ErrorLog directives should be configured appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 W22  Rule ID: SV-33135r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27990-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions of Apache's htpasswd.exe file(s) should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server’s htpasswd files (if present) must reflect proper ownership and permissions.
STIG ID: WG270 W22  Rule ID: SV-36561r1_rule  Vuln ID: V-2255
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28114-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions for all directories specified by ScriptAlias directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 W22  Rule ID: SV-33136r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27605-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions for all directories specified by ScriptAliasMatch directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 W22  Rule ID: SV-33136r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27226-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions for all directories specified by DocumentRoot directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 W22  Rule ID: SV-33136r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27575-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions for all directories specified by Alias directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 W22  Rule ID: SV-33136r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28134-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions for all directories specified by ServerRoot directives should be configred appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 W22  Rule ID: SV-33078r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27271-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions of Apache's /config directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 W22  Rule ID: SV-33078r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28147-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions of Apache's /bin directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 W22  Rule ID: SV-33078r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28005-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions of Apache's /logs directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 W22  Rule ID: SV-33078r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28188-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Windows permissions of Apache's /htdocs directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 W22  Rule ID: SV-33078r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28195-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The requried permssions for the file %SystemRoot%\System32\wscript.exe should be assigned.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the %SystemRoot%\System32\wscript.exe DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Wscript.exe and Cscript.exe must only be accessible by the SA and/or the web administrator.
STIG ID: WG470 W22  Rule ID: SV-33095r1_rule  Vuln ID: V-2264
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28056-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The required permissions for the file %SystemRoot%\System32\cscript.exe should be assigned</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the %SystemRoot%\System32\cscript.exe DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Wscript.exe and Cscript.exe must only be accessible by the SA and/or the web administrator.
STIG ID: WG470 W22  Rule ID: SV-33095r1_rule  Vuln ID: V-2264
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27816-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache web server be run with the appropriate privileges.</description>
      <parameters>
        <parameter>(1) Account type: ( privileged / non privileged )</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) My Computer / Manage / Configuration / Local Users and Groups / &lt;account name&gt;</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server, although started by superuser or privileged account, must run using a non-privileged account.
STIG ID: WG275 W22  Rule ID: SV-36607r1_rule  Vuln ID: V-13619
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27732-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's process ID (PID) file's Windows permissions should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The process ID (PID) file must be properly secured.
STIG ID: WA00530 W22  Rule ID: SV-33177r1_rule  Vuln ID: V-26305
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27466-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>Apache's Scoreboard file's Windows permissions should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.0 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ScoreBoard file must be properly secured.
STIG ID: WA00535 W22  Rule ID: SV-33178r1_rule  Vuln ID: V-26322
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28229-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The location of the Apache htpasswd file should be set correctly.</description>
      <parameters>
        <parameter>(1) directory path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Directory of htpasswd file</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 14. Authentication Mechanisms p22</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27438-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache User directive should be set correctly.</description>
      <parameters>
        <parameter>(1) user name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: User directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 8. User Oriented General Directives p13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28235-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache Group directive should be set correctly.</description>
      <parameters>
        <parameter>(1) group name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Group directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 8. User Oriented General Directives p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27975-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache Server Administrator email address should be set correctly.</description>
      <parameters>
        <parameter>(1) email address</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) 'ServerAdmin' line in Apache configuration file</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 8. User Oriented General Directives p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27783-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache ServerSignature directive should be set appropriately.</description>
      <parameters>
        <parameter>(1) On/Off/EMail</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ServerSignature directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27765-7' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache runtime rewriting engine should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) off/on</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: RewriteEngine directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 21. Deny HTTP TRACE Requests with Mod_Rewrite p33</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28057-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache ErrorDocument directive should be set correctly for HTTP 400 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 400' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27894-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 401 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 401' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27953-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 403 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 403' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27454-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 404 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 404' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27927-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 405 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 405' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27530-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 500 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 500' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 11. Web Server Software Obfuscation General Directives p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28220-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache user account should be locked or unlocked as appropriate.</description>
      <parameters>
        <parameter>(1) locked/unlocked</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 5. Lock Down the Apache Web User Account p11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28191-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Apache user account should be allowed root privileges as appropriate.</description>
      <parameters>
        <parameter>(1) allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 4. Create the Apache Web User Account p11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28003-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The group membership of the Apache user account should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/group</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 4. Create the Apache Web User Account p11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28224-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ownership of the Apache /etc/httpd/conf/passwd file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28002-4' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The group membership of the Apache /etc/httpd/conf/passwd file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28159-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The permissions for the Apache /etc/httpd/conf/passwd file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28024-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ownership of the Apache /var/www/html file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28259-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The group membership of the Apache /var/www/html file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27834-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The permissions for the Apache/var/www/html file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28187-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ownership of log files in Apache /var/log/httpd/ should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28151-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The group membership of any Apache files in /var/log/httpd/ should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27645-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The permissions of any Apache files in /var/log/httpd/ should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28132-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ownership of the Apache /etc/httpd/conf.d file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28249-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The group membership of the Apache /etc/httpd/conf.d file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27281-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The permissions for the Apache /etc/httpd/conf.d file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27346-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ownership of the Apache /usr/sbin/httpd file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27945-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The group membership of the Apache /usr/sbin/httpd file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28210-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The permissions for the Apache /usr/sbin/httpd file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28211-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The ownership of the Apache /usr/sbin/apachectl file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28157-6' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The group membership of the Apache /usr/sbin/apachectl file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28230-1' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The permissions for the Apache /usr/sbin/apachectl file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 19. Updating Ownership and Permissions for Enhanced Security p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28173-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Allow directive for the specified Directory directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Allow directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 13. Access Control Directives p21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28263-2' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The Deny directive for the specified Directory directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Deny directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 13. Access Control Directives p21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28260-8' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The "FollowSymLinks" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) FollowSymLinks / -FollowSymLinks / +FollowSymLinks / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p23</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27653-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The"Includes" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) Includes / -Includes / +Includes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28080-0' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The "IncludesNOEXEC" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) IncludesNoExec / -IncludesNoExec / +IncludesNoExec / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28165-9' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The "Indexes" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) Indexes / -Indexes / +Indexes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28252-5' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>The"MultiViews" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) MultiViews / -MultiViews / +MultiViews / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 15. Directory Functionality/Features Directives p24-25</reference>
      </references>
    </cce>
    <cce cce_id='CCE-28045-3' platform='apache-httpd2.0' modified='2013-02-11'>
      <description>testcgi should be installed as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) cgi-script directory</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Apache Benchmark for Unix For Apache Versions 1.3 and 2.0 Levels I and II'>L1 18. Remove Default/Unneeded Apache Files p27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27779-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Anonymous sharing of Apache's web content directories should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Set of shares</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters\NullSessionShares </technical_mechanism>
        <technical_mechanism>(2) defined by Local or Group Policy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web content directories must not be anonymously shared.
STIG ID: WG210 W22  Rule ID: SV-33109r1_rule  Vuln ID: V-2226
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27516-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache AllowOverride directive should be configured appropriately for web site root directories.</description>
      <parameters>
        <parameter>(1) AuthConfig / FileInfo / Indexes / Limit / Options / All / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: AllowOverride directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p17</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All interactive programs must be placed in a designated directory with appropriate permissions.
STIG ID: WG400 W22  Rule ID: SV-36644r1_rule  Vuln ID: V-2228
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27868-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The maximum password age setting for Apache's service account should be configured appropriately.</description>
      <parameters>
        <parameter>(1) number of days</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by Local or Group Policy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The service account used to run the web service must have its password changed at least    annually.
STIG ID: WG060 W22  Rule ID: SV-36489r1_rule  Vuln ID: V-2235
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27830-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apachce "MaxKeepAliveRequests" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MaxKeepAliveRequests directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.9.1 Denial of Service Mitigation (Level 1, Scorable) 
Add or modify the MaxKeepAliveRequests directive in the Apache configuration to have a value of 100 or more. p71</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The number of allowed simultaneous requests must be set.
STIG ID: WG110 W22  Rule ID: SV-33105r1_rule  Vuln ID: V-2240
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The number of allowed simultaneous requests must be set.
STIG ID: WG110 A22  Rule ID: SV-33018r1_rule  Vuln ID: V-2240
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27745-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All readable Apache web document directories should have their default webpage configured appropriately.</description>
      <parameters>
        <parameter>(1) exist / not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Directories (from Apache configuration file: DocumentRoot directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Each readable web document directory must contain either a default, home, index, or equivalent file.
STIG ID: WG170 W22  Rule ID: SV-33107r1_rule  Vuln ID: V-2245
Severity: CAT III  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27780-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Access to Apache's httpd.conf file should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by (ServerRoot)\conf\httpd.conf's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web administration tools must be restricted to the web manager and the web manager’s designees.
STIG ID: WG220 W22  Rule ID: SV-33072r1_rule  Vuln ID: V-2248
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27782-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's log_config_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) log_config_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.2 Enable the Log Config Module (Level 1, Scorable)
For dynamically loaded modules, add or modify the LoadModule directive so that it is present in the apache configuration as below and not commented out : LoadModule log_config_module modules/mod_log_config.so p12</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Logs of web server access and errors must be established and maintained.
STIG ID: WG240 W22  Rule ID: SV-33132r1_rule  Vuln ID: V-2250
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Logs of web server access and errors must be established and maintained.
STIG ID: WG240 A22  Rule ID: SV-33025r1_rule  Vuln ID: V-2250
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27839-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions for all files specified by CustomLog directives should be configured appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 W22  Rule ID: SV-33135r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27750-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions for all files specified by ErrorLog directives should be configured appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 W22  Rule ID: SV-33135r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27599-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions of Apache's htpasswd.exe file(s) should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server’s htpasswd files (if present) must reflect proper ownership and permissions.
STIG ID: WG270 W22  Rule ID: SV-36561r1_rule  Vuln ID: V-2255
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27799-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions for all directories specified by ScriptAlias directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 W22  Rule ID: SV-33136r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27705-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions for all directories specified by ScriptAliasMatch directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 W22  Rule ID: SV-33136r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27840-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions for all directories specified by DocumentRoot directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 W22  Rule ID: SV-33136r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27771-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions for all directories specified by Alias directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 W22  Rule ID: SV-33136r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27843-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions for all directories specified by ServerRoot directives should be configred appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 W22  Rule ID: SV-33078r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27240-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions of Apache's /config directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 W22  Rule ID: SV-33078r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27829-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions of Apache's /bin directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 W22  Rule ID: SV-33078r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27306-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions of Apache's /logs directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 W22  Rule ID: SV-33078r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27813-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Windows permissions of Apache's /htdocs directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 W22  Rule ID: SV-33078r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27773-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache site's robots.txt should be configured to disallow paths and files as appropriate.</description>
      <parameters>
        <parameter>(1) User-Agent</parameter>
        <parameter>(2) Disallowed path(s)|file(s)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) robots.txt</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must not respond to requests from public search engines.
STIG ID: WG310 W22  Rule ID: SV-28798r2_rule  Vuln ID: V-2260
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must not respond to requests from public search engines.
STIG ID: WG310 A22  Rule ID: SV-33028r1_rule  Vuln ID: V-2260
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27872-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's ssl_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) ssl_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.7.1 Install mod_ssl and/or mod_nss (Level 1, Scorable)
Ensure the mod_ssl and/or mod_nss is loaded in the Apache configuration: # httpd -M | egrep 'ssl_module|nss_module' p59</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 W22  Rule ID: SV-14297r4_rule Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 A22  Rule ID: SV-33029r1_rule  Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27740-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache SSLProtocol directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) SSLv2 / SSLv3 / TLSv1 / All</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: SSLProtocol directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.7.4 Restrict weak SSL Protocols and Ciphers (Level 1, Scorable)
Add or modify the following line in the Apache server level configuration and every virtual host that is SSL enabled: SSLProtocol -ALL +SSLv3 +TLSv1 p65</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 W22  Rule ID: SV-14297r4_rule Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 A22  Rule ID: SV-33029r1_rule  Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27576-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache SSLEngine directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) On / Off</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: SSLEngine directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 W22  Rule ID: SV-14297r4_rule Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: A private web server must utilize TLS v 1.0 or greater.
STIG ID: WG340 A22  Rule ID: SV-33029r1_rule  Vuln ID: V-2262
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27753-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The requried permssions for the file %SystemRoot%\System32\wscript.exe should be assigned.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the %SystemRoot%\System32\wscript.exe DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Wscript.exe and Cscript.exe must only be accessible by the SA and/or the web administrator.
STIG ID: WG470 W22  Rule ID: SV-33095r1_rule  Vuln ID: V-2264
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27598-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The required permissions for the file %SystemRoot%\System32\cscript.exe should be assigned</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the %SystemRoot%\System32\cscript.exe DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Wscript.exe and Cscript.exe must only be accessible by the SA and/or the web administrator.
STIG ID: WG470 W22  Rule ID: SV-33095r1_rule  Vuln ID: V-2264
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27380-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "ServerTokens" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Prod[uctOnly] / Major / Minor / Min[imal] / OS / Full</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ServerTokens directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.8.1 Limit Information in the Server Token (Level 1, Scorable)
Add or modify the ServerTokens directive as shown below to have the value of Prod or ProductOnly: ServerTokens Prod page 68</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.16 Software Information Leakage Protection p29</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server and/or operating system information must be protected.
STIG ID: WG520 W22  Rule ID: SV-33098r1_rule  Vuln ID: V-6724
Severity: CAT III  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server and/or operating system information must be protected.
STIG ID: WG520 A22  Rule ID: SV-36672r1_rule  Vuln ID: V-6724
Severity: CAT III  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27686-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache web server be run with the appropriate privileges.</description>
      <parameters>
        <parameter>(1) Account type: ( privileged / non privileged )</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) My Computer / Manage / Configuration / Local Users and Groups / &lt;account name&gt;</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server, although started by superuser or privileged account, must run using a non-privileged account.
STIG ID: WG275 W22  Rule ID: SV-36607r1_rule  Vuln ID: V-13619
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27469-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All Apache's online manual should be available or removed as appropriate.</description>
      <parameters>
        <parameter>(1) exist / not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) manual in the Server Root directory</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.4 Remove Default HTML Content (Level 1, Scorable)
Remove the Apache user manual content or comment out configurations referencing the manual # yum erase httpd-manual page 37</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All web server documentation, sample code, example applications, and tutorials must be  removed from a production web server.
STIG ID: WG385 W22  Rule ID: SV-33087r1_rule  Vuln ID: V-13621
Severity: CAT I  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All web server documentation, sample code, example applications, and tutorials must be  removed from a production web server.
STIG ID: WG385 A22  Rule ID: SV-32933r1_rule  Vuln ID: V-13621
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27870-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's demo CGI printenv.pl should be available or removed as appropriate</description>
      <parameters>
        <parameter>(1) exist / not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) (ServerRoot)\cgi-bin\printenv.pl</technical_mechanism>
        <technical_mechanism>(2) (ServerRoot)/cgi-bin/printenv.pl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.5 Remove Default CGI Content printenv (Level 1, Scorable)
Remove the printenv default CGI in cgi-bin directory if it is installed. # rm $APACHE_PREFIX/cgi-bin/printenv page 39</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.18 Remove Default Content p33</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All web server documentation, sample code, example applications, and tutorials must be  removed from a production web server.
STIG ID: WG385 W22  Rule ID: SV-33087r1_rule  Vuln ID: V-13621
Severity: CAT I  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: All web server documentation, sample code, example applications, and tutorials must be  removed from a production web server.
STIG ID: WG385 A22  Rule ID: SV-32933r1_rule  Vuln ID: V-13621
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27639-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache access log file data should be configured to contain the appropriate data elements.</description>
      <parameters>
        <parameter>(1) LogFormat Format String</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LogFormat directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.6.2 Configure the Access Log (Level 1, Scorable)
Add or modify the LogFormat directives in the Apache configuration to use the standard and recommended combined format show as shown below. LogFormat "%h %l %u %t \"%r\" %&gt;s %b \"%{Referer}i\" \"%{User-agent}i\"" combined</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.17 Logging p30</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file data must contain required data elements.
STIG ID: WG242 W22  Rule ID: SV-28654r2_rule  Vuln ID: V-13688
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file data must contain required data elements.
STIG ID: WG242 A22  Rule ID: SV-36642r1_rule  Vuln ID: V-13688
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27688-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "Timeout" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in seconds)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Timeout directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.9.1 Denial of Service Mitigation (Level 1, Scorable)
Add or modify the Timeout directive in the Apache configuration to have a value of 10 seconds or shorter. Timeout 10 page 71</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p21</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The Timeout directive must be properly set.
STIG ID: WA000-WWA020 W22  Rule ID: SV-32980r1_rule  Vuln ID: V-13724
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The Timeout directive must be properly set.
STIG ID: WA000-WWA020 A22  Rule ID: SV-32977r1_rule  Vuln ID: V-13724
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27456-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "KeepAlive" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) On / Off</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: KeepAlive directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.9.1 Denial of Service Mitigation (Level 1, Scorable)
Add or modify the KeepAlive directive in the Apache configuration to have a value of On, so that Keepalive connections are enabled. KeepAlive On page 71</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p21</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The KeepAlive directive must be enabled.
STIG ID: WA000-WWA022 W22  Rule ID: SV-32987r1_rule  Vuln ID: V-13725
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The KeepAlive directive must be enabled.
STIG ID: WA000-WWA022 A22  Rule ID: SV-32844r1_rule  Vuln ID: V-13725
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27330-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "KeepAliveTimeout" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in seconds)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: KeepAliveTimeout directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.9.1 Denial of Service Mitigation (Level 1, Scorable)
Add or modify the KeepAliveTimeout directive in the Apache configuration to have a value of 15 or less. KeepAliveTimeout 15 page 71</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p21</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The KeepAliveTimeout directive must be defined.
STIG ID: WA000-WWA024 W22  Rule ID: SV-32880r1_rule  Vuln ID: V-13726
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The KeepAliveTimeout directive must be defined.
STIG ID: WA000-WWA024 A22  Rule ID: SV-32877r1_rule  Vuln ID: V-13726
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27877-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "FollowSymLinks" setting for all "Options" directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) FollowSymLinks / -FollowSymLinks / +FollowSymLinks / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.3 Minimize Options for Other Directories (Level 1, Scorable)
FollowSymLinks &amp; SymLinksIfOwnerMatch – The following of symbolic links is not recommended and should be disabled if possible. Page 35</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The FollowSymLinks setting must be disabled.
STIG ID: WA000-WWA052 W22  Rule ID: SV-33001r1_rule  Vuln ID: V-13732
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The FollowSymLinks setting must be disabled.
STIG ID: WA000-WWA052 A22  Rule ID: SV-40129r1_rule  Vuln ID: V-13732
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27764-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "Includes" setting for all "Options" directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Includes / -Includes / +Includes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.3 Minimize Options for Other Directories Includes &amp; IncludesNOEXEC – The IncludesNOEXEC option should only be needed when server side includes are required. The full Includes option should not be used as it also allows execution of arbitrary shell commands. Page 35</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Server side includes (SSIs) must run with execution capability disabled.
STIG ID: WA000-WWA054 W22  Rule ID: SV-33003r1_rule  Vuln ID: V-13733
Severity: CAT I  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Server side includes (SSIs) must run with execution capability disabled.
STIG ID: WA000-WWA054 A22  Rule ID: SV-32753r1_rule  Vuln ID: V-13733
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27666-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "IncludesNoExec" setting for all "Options" directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) IncludesNoExec / -IncludesNoExec / +IncludesNoExec / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.3 Minimize Options for Other Directories Includes &amp; IncludesNOEXEC – The IncludesNOEXEC option should only be needed when server side includes are required. The full Includes option should not be used as it also allows execution of arbitrary shell commands. Page 35</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Server side includes (SSIs) must run with execution capability disabled.
STIG ID: WA000-WWA054 W22  Rule ID: SV-33003r1_rule  Vuln ID: V-13733
Severity: CAT I  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Server side includes (SSIs) must run with execution capability disabled.
STIG ID: WA000-WWA054 A22  Rule ID: SV-32753r1_rule  Vuln ID: V-13733
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27757-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "MultiViews" setting for all "Options" directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) MultiViews / -MultiViews / +MultiViews / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.3 Minimize Options for Other Directories (Level 1, Scorable)
Multiviews – Is appropriate if content negotiation is required such as for multiple language are supported. Page 35</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The MultiViews directive must be disabled.
STIG ID: WA000-WWA056 W22  Rule ID: SV-33004r1_rule  Vuln ID: V-13734
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The MultiViews directive must be disabled.
STIG ID: WA000-WWA056 A22  Rule ID: SV-32754r1_rule  Vuln ID: V-13734
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27657-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "Indexes" setting for all "Options" directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Indexes / -Indexes / +Indexes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.3 Minimize Options for Other Directories (Level 1, Scorable)
Indexes – The Indexes option causes automatic generation of indexes, if the default index page is missing, and should be disabled unless required. Page 35</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Directory indexing must be disabled on directories not containing index files.
STIG ID: WA000-WWA058 W22  Rule ID: SV-33006r1_rule  Vuln ID: V-13735
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Directory indexing must be disabled on directories not containing index files.
STIG ID: WA000-WWA058 A22  Rule ID: SV-32755r1_rule  Vuln ID: V-13735
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27618-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "LimitRequestBody" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in bytes)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestBody directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.9.2 Buffer Overflow Mitigation (Level 2, Scorable)
Add or modify the LimitRequestBody directive in the Apache configuration to have a value of 102400 (100K) or less. Please read the Apache documentation so that it is understood that this directive will limit the size of file up-loads to the web server. LimitRequestBody 102400 page 73</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.14 Buffer Overflow Protection Tuning p23</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request message body size must be limited.
STIG ID: WA000-WWA060 W22  Rule ID: SV-33008r1_rule  Vuln ID: V-13736
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request message body size must be limited.
STIG ID: WA000-WWA060 A22  Rule ID: SV-32756r1_rule  Vuln ID: V-13736
Severity: CAT II  Class: Unclass+G66</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27741-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "LimitRequestFields" directive should be configured appropriately</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestFields directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.9.2 Buffer Overflow Mitigation (Level 2, Scorable)
Add or modify the LimitRequestFields directive in the Apache configuration to have a value of 100 or less. If the directive is not present the default depends on a compile time configuration, but defaults to a value of 100. LimitRequestFields 100 page 73</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.14 Buffer Overflow Protection Tuning p24</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request header fields must be limited.
STIG ID: WA000-WWA062 W22  Rule ID: SV-33009r1_rule  Vuln ID: V-13737
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request header fields must be limited.
STIG ID: WA000-WWA062 A22  Rule ID: SV-32757r1_rule  Vuln ID: V-13737
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27554-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "LimitRequestFieldSizeBody" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value (in bytes)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestFieldSizeBody directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.9.2 Buffer Overflow Mitigation (Level 2, Scorable)
Add or modify the LimitRequestFieldsize directive in the Apache configuration to have a value of 1024 or less. LimitRequestFieldsize 1024 page 73</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.14 Buffer Overflow Protection Tuning p24</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request header field size must be limited.
STIG ID: WA000-WWA064 W22  Rule ID: SV-33010r1_rule  Vuln ID: V-13738
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request header field size must be limited.
STIG ID: WA000-WWA064 A22  Rule ID: SV-32766r1_rule  Vuln ID: V-13738
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27426-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "LimitRequestline" directive should be configured appropriatley.</description>
      <parameters>
        <parameter>(1) Number value (in bytes)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitRequestLine directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.9.2 Buffer Overflow Mitigation (Level 2, Scorable)
Add or modify the LimitRequestline directive in the Apache configuration to have a value of 512 or shorter. LimitRequestline 512 page 72</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.14 Buffer Overflow Protection Tuning p24</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request line must be limited.
STIG ID: WA000-WWA066 W22  Rule ID: SV-33011r1_rule  Vuln ID: V-13739
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The HTTP request line must be limited.
STIG ID: WA000-WWA066 A22  Rule ID: SV-32768r1_rule  Vuln ID: V-13739
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27822-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The path for Apache sites error log files should be configured appropriately.</description>
      <parameters>
        <parameter>(1) File path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ErrorLog directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.6.1 Configure the Error Log (Level 1, Scorable)
Add an ErrorLog directive if not already configured. The file path may be relative or absolute, or the logs may be configured to be sent to a syslog server. ErrorLog "logs/error_log" Add a similar ErrorLog directive for each virtual host configured if the virtual host will have different people responsible for the web site. Each responsible individual or organization needs access to their own web logs, and needs the skills/training/tools for monitor the logs. page 50</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.5 Syslog Logging p44-45</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Error logging must be enabled.
STIG ID: WA00605 W22  Rule ID: SV-33147r1_rule  Vuln ID: V-26279
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Error logging must be enabled.
STIG ID: WA00605 A22  Rule ID: SV-33192r1_rule  Vuln ID: V-26279
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27794-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache system logging should be configured appropriately.</description>
      <parameters>
        <parameter>(1) File path | pipe</parameter>
        <parameter>(2)  LogFormat | nickname</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: CustomLog directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.6.2 Configure the Access Log (Level 1, Scorable)
Add or modify the CustomLog directives in the Apache configuration to use the combined format with an appropriate log file, syslog facility or piped logging utility. CustomLog log/access_log combined
Add a similar CustomLog directives for each virtual host configured if the virtual host will have different people responsible for the web site. Each responsible individual or organization needs access to their own web logs, and needs the skills/training/tools for monitor the logs. page 51</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.17 Logging p31</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: System logging must be enabled.
STIG ID: WA00615 W22  Rule ID: SV-33151r1_rule  Vuln ID: V-26281
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: System logging must be enabled.
STIG ID: WA00615 A22  Rule ID: SV-33206r1_rule  Vuln ID: V-26281
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27879-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "LogLevel" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) debug / info / notice / warn / error / crit / alert / emerg</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LogLevel directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.6.1 Configure the Error Log (Level 1, Scorable)
Add or modify the LogLevel in the apache configuration to have a value of notice or lower. Note that is it is compliant to have a value of info or debug if there is a need for a more verbose log and the storage and monitoring processes are capable of handling the extra load. The recommended value is notice. LogLevel notice page 50</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.17 Logging p31</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The LogLevel directive must be enabled.
STIG ID: WA00620 W22  Rule ID: SV-33153r1_rule  Vuln ID: V-26282
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The LogLevel directive must be enabled.
STIG ID: WA00620 A22  Rule ID: SV-33207r1_rule  Vuln ID: V-26282
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27132-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Web Distributed Authoring and Versioning (WebDav) dav_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) dav_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.3 Disable WebDAV modules (Level 1, Scorable)
For dynamically loaded modules comment out or remove the LoadModule directive for mod_dav, and mod_dav_fs modules the from the httpd.conf file. ##LoadModule dav_module modules/mod_dav.so ##LoadModule dav_fs_module modules/mod_dav_fs.so page 13</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web Distributed Authoring and Versioning (WebDAV) must be disabled.
STIG ID: WA00505 W22  Rule ID: SV-33169r1_rule  Vuln ID: V-26287
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web Distributed Authoring and Versioning (WebDAV) must be disabled.
STIG ID: WA00505 A22  Rule ID: SV-33216r1_rule  Vuln ID: V-26287
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27861-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Web Distributed Authoring and Versioning (WebDav) dav_fs_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) dav_fs_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.3 Disable WebDAV modules (Level 1, Scorable)
For dynamically loaded modules comment out or remove the LoadModule directive for mod_dav, and mod_dav_fs modules the from the httpd.conf file. ##LoadModule dav_module modules/mod_dav.so ##LoadModule dav_fs_module modules/mod_dav_fs.so page 13</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web Distributed Authoring and Versioning (WebDAV) must be disabled.
STIG ID: WA00505 W22  Rule ID: SV-33169r1_rule  Vuln ID: V-26287
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web Distributed Authoring and Versioning (WebDAV) must be disabled.
STIG ID: WA00505 A22  Rule ID: SV-33216r1_rule  Vuln ID: V-26287
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27583-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Web Distributed Authoring and Versioning (WebDav) dav_lock_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) dav_lock_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web Distributed Authoring and Versioning (WebDAV) must be disabled.
STIG ID: WA00505 W22  Rule ID: SV-33169r1_rule  Vuln ID: V-26287
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web Distributed Authoring and Versioning (WebDAV) must be disabled.
STIG ID: WA00505 A22  Rule ID: SV-33216r1_rule  Vuln ID: V-26287
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27852-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's info_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) info_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.8 Disable Info module (Level 1, Scorable)
a) For source builds with static modules run the Apache ./configure script without including the mod_info in the --enable-modules= configure script options. $ cd $DOWNLOAD/httpd-2.2.22 $ ./configure
b) For dynamically loaded modules comment out or remove the LoadModule directive for the mod_info module from the httpd.conf file. ##LoadModule info_module modules/mod_info.so Page 18</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server status module will be disabled.
STIG ID: WA00510 W22  Rule ID: SV-33171r1_rule  Vuln ID: V-26294
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server status module will be disabled.
STIG ID: WA00510 A22  Rule ID: SV-33218r1_rule  Vuln ID: V-26294
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27357-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's status_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) status_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.4 Disable Status module (Level 1, Scorable)
a) For source builds with static modules run the Apache ./configure script with the --disable-status configure script options. $ cd $DOWNLOAD/httpd-2.2.22 $ ./configure --disable-status
b) For dynamically loaded modules comment out or remove the LoadModule directive for the mod_status module from the httpd.conf file. ##LoadModule status_module modules/mod_status.so page 14</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server status module will be disabled.
STIG ID: WA00510 W22  Rule ID: SV-33171r1_rule  Vuln ID: V-26294
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server status module will be disabled.
STIG ID: WA00510 A22  Rule ID: SV-33218r1_rule  Vuln ID: V-26294
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27825-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's proxy_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) proxy_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.6 Disable Proxy Modules (Level 1, Scorable)
a) For source builds with static modules run the Apache ./configure script without including the mod_proxy in the --enable-modules= configure script options. $ cd $DOWNLOAD/httpd-2.2.22 $ ./configure
b) For dynamically loaded modules comment out or remove the LoadModule directive for mod_proxy module and all other proxy modules the from the httpd.conf file. ##LoadModule proxy_module modules/mod_proxy.so Page 16</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 W22  Rule ID: SV-33173r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 A22  Rule ID: SV-33220r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27788-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's proxy_ftp_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) proxy_ftp_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.6 Disable Proxy Modules (Level 1, Scorable)
a) For source builds with static modules run the Apache ./configure script without including the mod_proxy in the --enable-modules= configure script options. $ cd $DOWNLOAD/httpd-2.2.22 $ ./configure
b) For dynamically loaded modules comment out or remove the LoadModule directive for mod_proxy module and all other proxy modules the from the httpd.conf file. ##LoadModule proxy_ftp_module modules/mod_proxy_ftp.so Page 16</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 W22  Rule ID: SV-33173r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 A22  Rule ID: SV-33220r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27881-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's proxy_http_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) proxy_http_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.6 Disable Proxy Modules (Level 1, Scorable)
a) For source builds with static modules run the Apache ./configure script without including the mod_proxy in the --enable-modules= configure script options. $ cd $DOWNLOAD/httpd-2.2.22 $ ./configure
b) For dynamically loaded modules comment out or remove the LoadModule directive for mod_proxy module and all other proxy modules the from the httpd.conf file. ##LoadModule proxy_http_module modules/mod_proxy_http.so Page 16</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 W22  Rule ID: SV-33173r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 A22  Rule ID: SV-33220r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27579-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's proxy_connect_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) proxy_connect_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.6 Disable Proxy Modules (Level 1, Scorable)
a) For source builds with static modules run the Apache ./configure script without including the mod_proxy in the --enable-modules= configure script options. $ cd $DOWNLOAD/httpd-2.2.22 $ ./configure
b) For dynamically loaded modules comment out or remove the LoadModule directive for mod_proxy module and all other proxy modules the from the httpd.conf file. ##LoadModule proxy_connect_module modules/mod_proxy_connect.so Page 16</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 W22  Rule ID: SV-33173r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 A22  Rule ID: SV-33220r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27824-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's proxy_ajp_module should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>(1) proxy_ajp_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.6 Disable Proxy Modules (Level 1, Scorable)
a) For source builds with static modules run the Apache ./configure script without including the mod_proxy in the --enable-modules= configure script options. $ cd $DOWNLOAD/httpd-2.2.22 $ ./configure
b) For dynamically loaded modules comment out or remove the LoadModule directive for mod_proxy module and all other proxy modules the from the httpd.conf file. ##LoadModule proxy_connect_module modules/mod_proxy_ajp.so Page 16</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 W22  Rule ID: SV-33173r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 A22  Rule ID: SV-33220r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27887-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's proxy_balancer_module should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) proxy_balancer_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.6 Disable Proxy Modules (Level 1, Scorable)
a) For source builds with static modules run the Apache ./configure script without including the mod_proxy in the --enable-modules= configure script options. $ cd $DOWNLOAD/httpd-2.2.22 $ ./configure
b) For dynamically loaded modules comment out or remove the LoadModule directive for mod_proxy module and all other proxy modules the from the httpd.conf file. ##LoadModule proxy_balancer_module modules/mod_proxy_balancer.so Page 16</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 W22  Rule ID: SV-33173r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must not be configured as a proxy server.
STIG ID: WA00520 A22  Rule ID: SV-33220r1_rule  Vuln ID: V-26299
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27682-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>User-specific directories should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) userdir_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.7 Disable User Directories Modules (Level 1, Scorable)
1. For source builds with static modules run the Apache ./configure script with the --disable-userdir configure script options. $ cd $DOWNLOAD/httpd-2.2.22 $ ./configure --disable-userdir
2. For dynamically loaded modules comment out or remove the LoadModule directive for mod_userdir module from the httpd.conf file. ##LoadModule userdir_module modules/mod_userdir.so Page 17</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: User specific directories must not be globally enabled.
STIG ID: WA00525 W22  Rule ID: SV-33175r1_rule  Vuln ID: V-26302
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: User specific directories must not be globally enabled.
STIG ID: WA00525 A22  Rule ID: SV-33221r1_rule  Vuln ID: V-26302
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27845-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's process ID (PID) file's Windows permissions should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The process ID (PID) file must be properly secured.
STIG ID: WA00530 W22  Rule ID: SV-33177r1_rule  Vuln ID: V-26305
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27819-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's Scoreboard file's Windows permissions should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ScoreBoard file must be properly secured.
STIG ID: WA00535 W22  Rule ID: SV-33178r1_rule  Vuln ID: V-26322
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27510-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Order directive for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Allow,Deny / Deny,Allow / Mutual-failure</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Order directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.4.1 Deny Access to OS Root Directory (Level 1, Scorable)
Ensure there is a single Order directive and set the value to deny, allow Page 27</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 W22  Rule ID: SV-33180r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 A22  Rule ID: SV-33226r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27415-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Allow Directive for the OS root should be configured appropriately</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Allow directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.4.1 Deny Access to OS Root Directory (Level 1, Scorable)
Remove any Allow directives from the root &lt;Directory&gt; element. allow Page 27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p14-15</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 W22  Rule ID: SV-33180r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 A22  Rule ID: SV-33226r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27684-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Deny Directive for the OS root should be configured appropriately</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Deny directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.4.1 Deny Access to OS Root Directory (Level 1, Scorable)
Ensure there is a Deny directive, and set the value to from all. allow Page 27</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p14-15</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 W22  Rule ID: SV-33180r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to explicitly deny access to the OS root.
STIG ID: WA00540 A22  Rule ID: SV-33226r1_rule  Vuln ID: V-26323
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27067-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "ExecCGI" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) ExecCGI / -ExecCGI/ +ExecCGI / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.1 Restrict Options for the OS Root Directory (Level 1, Scorable)
Set the value for Options to None. Page 33</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 W22  Rule ID: SV-33182r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27134-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "FollowSymLinks" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) FollowSymLinks / -FollowSymLinks / +FollowSymLinks / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.1 Restrict Options for the OS Root Directory (Level 1, Scorable)
Set the value for Options to None. Page 33</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 W22  Rule ID: SV-33182r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27679-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "Includes" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Includes / -Includes / +Includes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.1 Restrict Options for the OS Root Directory (Level 1, Scorable)
Set the value for Options to None. Page 33</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 W22  Rule ID: SV-33182r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27506-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "IncludesNoExec" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) IncludesNoExec / -IncludesNoExec / +IncludesNoExec / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.1 Restrict Options for the OS Root Directory (Level 1, Scorable)
Set the value for Options to None. Page 33</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 W22  Rule ID: SV-33182r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27545-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "Indexes" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Indexes / -Indexes / +Indexes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.1 Restrict Options for the OS Root Directory (Level 1, Scorable)
Set the value for Options to None. Page 33</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 W22  Rule ID: SV-33182r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27692-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "MultiViews" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) MultiViews / -MultiViews / +MultiViews / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.1 Restrict Options for the OS Root Directory (Level 1, Scorable)
Set the value for Options to None. Page 33</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 W22  Rule ID: SV-33182r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27806-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "SymLinksIfOwnerMatch" setting for all "Options" directives for the OS root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) SymLinksIfOwnerMatch / -SymLinksIfOwnerMatch / +SymLinksIfOwnerMatch / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in OS root Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.1 Restrict Options for the OS Root Directory (Level 1, Scorable)
Set the value for Options to None. Page 33</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 W22  Rule ID: SV-33182r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server options for the OS root must be disabled.
STIG ID: WA00545 A22  Rule ID: SV-33213r1_rule  Vuln ID: V-26324
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27531-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "TraceEnable" directive should be configured appropriatley.</description>
      <parameters>
        <parameter>(1) on / off / extended</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: TraceEnable directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.8 Disable HTTP TRACE Method (Level 1, Scorable)
Add a TraceEnable directive to the server level configuration with a value of off. Server level configuration is the top level configuration, not nested within any other directives like &lt;Directory&gt; or &lt;Location&gt;. TraceEnable off Page 42-43</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The TRACE method must be disabled.
STIG ID: WA00550 W22  Rule ID: SV-33183r1_rule  Vuln ID: V-26325
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The TRACE method must be disabled.
STIG ID: WA00550 A22  Rule ID: SV-33227r1_rule  Vuln ID: V-26325
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27862-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's listening IP address should be configured appropriately.</description>
      <parameters>
        <parameter>(1) IP-address</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Listen directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.9.3 Restrict Listen Directive (Level 2, Scorable)
The Apache Listen directive specifies the IP addresses and port numbers the Apache web server will listen for requests. Rather than be unrestricted to listen on all IP addresses available to the system, the specific IP address or addresses intended should be explicitly specified. Specifically a Listen directive with no IP address specified, or with an IP address of zeros should not be used.  Page 74</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to listen on a specific IP address and port.
STIG ID: WA00555 W22  Rule ID: SV-33184r1_rule  Vuln ID: V-26326
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to listen on a specific IP address and port.
STIG ID: WA00555 A22  Rule ID: SV-33228r1_rule  Vuln ID: V-26326
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27246-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's listening port should be configured appropriately.</description>
      <parameters>
        <parameter>(1) port number</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Listen directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.9.3 Restrict Listen Directive (Level 2, Scorable)
The Apache Listen directive specifies the IP addresses and port numbers the Apache web server will listen for requests. Rather than be unrestricted to listen on all IP addresses available to the system, the specific IP address or addresses intended should be explicitly specified. Specifically a Listen directive with no IP address specified, or with an IP address of zeros should not be used.  Page 74</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to listen on a specific IP address and port.
STIG ID: WA00555 W22  Rule ID: SV-33184r1_rule  Vuln ID: V-26326
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server must be configured to listen on a specific IP address and port.
STIG ID: WA00555 A22  Rule ID: SV-33228r1_rule  Vuln ID: V-26326
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27733-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ScriptAlias for the specified directory should be configured appropriately.</description>
      <parameters>
        <parameter>(1) url-path</parameter>
        <parameter>(2) TARGET: directory path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ScriptAlias directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The URL-path name must be set to the file path name or the directory path name.
STIG ID: WA00560 W22  Rule ID: SV-33185r1_rule  Vuln ID: V-26327
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The URL-path name must be set to the file path name or the directory path name.
STIG ID: WA00560 A22  Rule ID: SV-33229r1_rule  Vuln ID: V-26327
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27759-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Automatic directory indexing should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) autoindex_module</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LoadModule directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.2.5 Disable Autoindex module (Level 1, Scorable)
For source builds with static modules run the Apache ./configure script with the --disable-autoindex configure script options. $ cd $DOWNLOAD/httpd-2.2.22 $ ./configure –disable-autoindex
b) For dynamically loaded modules comment out or remove the LoadModule directive for mod_autoindex module the from the httpd.conf file. ## LoadModule autoindex_module modules/mod_autoindex.so Page 14-15</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Automatic directory indexing must be disabled.
STIG ID: WA00515 W22  Rule ID: SV-33225r1_rule  Vuln ID: V-26368
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Automatic directory indexing must be disabled.
STIG ID: WA00515 A22  Rule ID: SV-33219r1_rule  Vuln ID: V-26368
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27536-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache AllowOverride Directive should be configured appropriately for operating system root directories.</description>
      <parameters>
        <parameter>(1) AuthConfig / FileInfo / Indexes / Limit / Options / All / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: AllowOverride directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.4.3 Restrict OverRide for the OS Root Directory (Level 1, Scorable)
Set the value for AllowOverride to None. Page 30-31</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p17</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ability to override the access configuration for the OS root directory must be disabled.
STIG ID: WA00547 W22  Rule ID: SV-33237r1_rule  Vuln ID: V-26393
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ability to override the access configuration for the OS root directory must be disabled.
STIG ID: WA00547 A22  Rule ID: SV-33232r1_rule  Vuln ID: V-26393
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27776-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Permitted HTTP request methods should be configured appropriately.</description>
      <parameters>
        <parameter>(1) methods</parameter>
        <parameter>(2) access control directives</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: LimitExecpt directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.7 Limit HTTP Request Methods (Level 1, Scorable)
For normal web server operation, you will typically need to allow only the GET, HEAD and POST request methods. Page 40-41</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: HTTP request methods must be limited.
STIG ID: WA00565 W22  Rule ID: SV-33238r1_rule  Vuln ID: V-26396
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: HTTP request methods must be limited.
STIG ID: WA00565 A22  Rule ID: SV-33236r1_rule  Vuln ID: V-26396
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27677-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Anonymous sharing of Apache's web content directories with nfs should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Set of shares</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/exports</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Windows Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web content directories must not be anonymously shared.
STIG ID: WG210 A22  Rule ID: SV-33022r1_rule  Vuln ID: V-2226
Severity: CAT II  Class: Unclass</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>AC-3(4).1
CM-6.1 (ii)
CM-7.1 (ii)</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>CCI-001362
CCI-001588
CCI-000381</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27612-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Anonymous sharing of Apache's web content directories with smb should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Set of shares</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/samba/smb.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web content directories must not be anonymously shared.
STIG ID: WG210 A22  Rule ID: SV-33022r1_rule  Vuln ID: V-2226
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27000-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>File permissions for httpd.conf should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web administration tools must be restricted to the web manager and the web manager’s designees.
STIG ID: WG220 A22  Rule ID: SV-32948r1_rule  Vuln ID: V-2248
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27890-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The httpd.conf file should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web administration tools must be restricted to the web manager and the web manager’s designees.
STIG ID: WG220 A22  Rule ID: SV-32948r1_rule  Vuln ID: V-2248
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27648-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The httpd.conf file should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web administration tools must be restricted to the web manager and the web manager’s designees.
STIG ID: WG220 A22  Rule ID: SV-32948r1_rule  Vuln ID: V-2248
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27400-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The file permissions for all files specified by CustomLog directives should be configured appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27304-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All files specified by CustomLog directives should be owned by the appropriate user</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27876-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All files specified by CustomLog directives should be owned by the appropriate group</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27864-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions for all files specified by ErrorLog directives should be configured appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27724-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All files specified by ErrorLog directives should be owned by the appropriate user</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27494-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All files specified by ErrorLog directives should be owned by the appropriate group</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Log file access must be restricted to System Administrators, Web Administrators or Auditors.
STIG ID: WG250 A22  Rule ID: SV-33033r1_rule  Vuln ID: V-2252
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27481-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions of Apache's htpasswd file should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server’s htpasswd files (if present) must reflect proper ownership and permissions.
STIG ID: WG270 A22  Rule ID: SV-36478r1_rule  Vuln ID: V-2255
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27332-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The htpasswd should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server’s htpasswd files (if present) must reflect proper ownership and permissions.
STIG ID: WG270 A22  Rule ID: SV-36478r1_rule  Vuln ID: V-2255
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27873-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The htpasswd file should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web server’s htpasswd files (if present) must reflect proper ownership and permissions.
STIG ID: WG270 A22  Rule ID: SV-36478r1_rule  Vuln ID: V-2255
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27292-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions for all directories specified by ScriptAlias directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.5 Apache Directory and File Permissions (Level 1, Scorable)
The permission on the Apache directories should be rwxr-xr-x (755) and the file permissions should be similar except not executable if executable is not appropriate.  Page 22-23</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27282-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All directories specified by ScriptAlias directives should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27777-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All directories specified by ScriptAlias directives should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27619-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions for all directories specified by ScriptAliasMatch directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.5 Apache Directory and File Permissions (Level 1, Scorable)
The permission on the Apache directories should be rwxr-xr-x (755) and the file permissions should be similar except not executable if executable is not appropriate.  Page 22-23</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27884-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All directories specified by ScriptAliasMatch directives should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27384-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All directories specified by ScriptAliasMatch directives should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27772-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions for all directories specified by DocumentRoot directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.5 Apache Directory and File Permissions (Level 1, Scorable)
The permission on the Apache directories should be rwxr-xr-x (755) and the file permissions should be similar except not executable if executable is not appropriate.  Page 22-23</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27492-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All directories specified by DocumentRoot directives should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27664-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All directories specified by DocumentRoot directives should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27627-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions for all directories specified by Alias directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.5 Apache Directory and File Permissions (Level 1, Scorable)
The permission on the Apache directories should be rwxr-xr-x (755) and the file permissions should be similar except not executable if executable is not appropriate.  Page 22-23</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27672-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All directories specified by Alias directives should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27460-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All directories specified by Alias directives should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SITE 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 A22  Rule ID: SV-33027r1_rule  Vuln ID: V-2258
Severity: CAT I  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27787-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions for all directories specified by ServerRoot directives should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27548-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All directories specified by ServerRoot directives should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27826-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>All directories specified by ServerRoot directives should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-26950-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions of Apache's configuration directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.5 Apache Directory and File Permissions (Level 1, Scorable)
The permission on the Apache directories should be rwxr-xr-x (755) and the file permissions should be similar except not executable if executable is not appropriate.  Page 22-23</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27833-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's configuration directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27800-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's configuration directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27911-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions of Apache's /bin directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.5 Apache Directory and File Permissions (Level 1, Scorable)
Perform the following to set the permissions on the $APACHE_PREFIX directories, and then remove other read permissions on the bin directory and its contents:
23 | P a g e
# chmod –R u=rwX,g=rX,o=rX $APACHE_PREFIX # chmod –R u=rwX,g=rX,o=X $APACHE_PREFIX/bin  Page 22-23</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27709-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's /bin directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27685-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's /bin directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27540-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions of Apache's /logs directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.5 Apache Directory and File Permissions (Level 1, Scorable)
The permission on the Apache directories should be rwxr-xr-x (755) and the file permissions should be similar except not executable if executable is not appropriate.  Page 22-23</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27818-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's /logs directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27602-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's /logs directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27041-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions of Apache's /htdocs directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.5 Apache Directory and File Permissions (Level 1, Scorable)
The permission on the Apache directories should be rwxr-xr-x (755) and the file permissions should be similar except not executable if executable is not appropriate. … exception in some cases may have a designated group with write access for the Apache web document root ($APACHE_PREFIX/htdocs) are likely to need a designated group to allow web content to be updated.</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27699-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's /htdocs directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27866-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's /htdocs directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
the Apache web document root ($APACHE_PREFIX/htdocs) are likely to need a designated group to allow web content to be updated (such as webupdate) through a change management process. Page 21</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27793-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Unix permissions of Apache's /cgi-bin directory should be configred appropriately</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.5 Apache Directory and File Permissions (Level 1, Scorable)
The permission on the Apache directories should be rwxr-xr-x (755) and the file permissions should be similar except not executable if executable is not appropriate.  Page 22-23</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27919-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's /cgi-bin directory should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27820-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's /cgi-bin directory should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.4 Apache Directory and File Ownership (Level 1, Scorable)
The Apache directories and files should be owned by root with the root (or root equivalent) group. Page 21-22</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 A22  Rule ID: SV-32938r1_rule  Vuln ID: V-2259
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27435-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "StartServers" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: StartServers directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p22</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The httpd.conf StartServers directive must be set properly.
STIG ID: WA000-WWA026 A22  Rule ID: SV-36645r1_rule  Vuln ID: V-13727
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27449-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "MinSpareServers" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MinSpareServers directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p22</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The httpd.conf MinSpareServers directive must be set properly. 
STIG ID: WA000-WWA028 A22  Rule ID: SV-36646r1_rule  Vuln ID: V-13728
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27810-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "MaxSpareServers" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MaxSpareServers directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p22</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The httpd.conf MaxSpareServers directive must be set properly. 
STIG ID: WA000-WWA030 A22  Rule ID: SV-36648r1_rule  Vuln ID: V-13729
Severity: CAT III  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27848-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache "MaxClients" directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Number value</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: MaxClients directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.13 Denial of Service Prevention Tuning p22</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The httpd.conf MaxClients directive must be set properly. 
STIG ID: WA000-WWA032 A22  Rule ID: SV-36649r1_rule  Vuln ID: V-13730
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27696-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's process ID (PID) file's Unix permissions should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.8 Pid File Security (Level 1, Scorable)
Change the permissions so that the directory is only writable by root, or the user under which apache initially starts up (default is root), Page 25</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The process ID (PID) file must be properly secured.
STIG ID: WA00530 A22  Rule ID: SV-33222r1_rule  Vuln ID: V-26305
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27851-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's process ID (PID) file should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.8 Pid File Security (Level 1, Scorable)
Change the ownership and group to be root:root, if not already. Page 25</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The process ID (PID) file must be properly secured.
STIG ID: WA00530 A22  Rule ID: SV-33222r1_rule  Vuln ID: V-26305
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27930-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's process ID (PID) file should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.8 Pid File Security (Level 1, Scorable)
Change the ownership and group to be root:root, if not already. Page 25</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The process ID (PID) file must be properly secured.
STIG ID: WA00530 A22  Rule ID: SV-33222r1_rule  Vuln ID: V-26305
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27126-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's Scoreboard file's Unix permissions should be configured appropriately.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.9 ScoreBoard File Security (Level 1, Scorable)
Change the permissions so that the directory is only writable by root, or the user under which apache initially starts up (default is root), Page 26</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ScoreBoard file must be properly secured.
STIG ID: WA00535 A22  Rule ID: SV-33223r1_rule  Vuln ID: V-26322
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27815-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's scoreboard file should be owned by the appropriate user.</description>
      <parameters>
        <parameter>(1) user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.9 ScoreBoard File Security (Level 1, Scorable)
Change the ownership and group to be root:root, if not already. Page 26</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ScoreBoard file must be properly secured.
STIG ID: WA00535 A22  Rule ID: SV-33223r1_rule  Vuln ID: V-26322
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27859-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>Apache's scoreboard (PID) file should be owned by the appropriate group.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.9 ScoreBoard File Security (Level 1, Scorable)
Change the ownership and group to be root:root, if not already. Page 26</reference>
        <reference resource_id='DISA STIG Apache SERVER 2.2 for Unix Release: 1 Benchmark Date: 23 Nov 2011'>Rule Title: The ScoreBoard file must be properly secured.
STIG ID: WA00535 A22  Rule ID: SV-33223r1_rule  Vuln ID: V-26322
Severity: CAT II  Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27667-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The location of the Apache htpasswd file should be set correctly.</description>
      <parameters>
        <parameter>(1) directory path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Directory of htpasswd file</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.10 Restrict Access to .ht* files (Level 1, Scorable)
Also a common name for web password and group files is .htpasswd and .htgroup. Neither of these files should be placed in the document root Page 45</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27756-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache User directive should be set correctly.</description>
      <parameters>
        <parameter>(1) user name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: User directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.1 Run the Apache Web Server as a non-root user (Level 1, Scorable)
Configure the Apache user and group in the Apache configuration file httpd.conf: User apache Page 19</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.6 Creating the Apache User and Group Accounts p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27566-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache Group directive should be set correctly.</description>
      <parameters>
        <parameter>(1) group name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Group directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.1 Run the Apache Web Server as a non-root user (Level 1, Scorable)
Configure the Apache user and group in the Apache configuration file httpd.conf: Group apache Page 19</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.6 Creating the Apache User and Group Accounts p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27883-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache ServerSignature directive should be set appropriately.</description>
      <parameters>
        <parameter>(1) On/Off/EMail</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: ServerSignature directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.8.2 Limit Information in the Server Signature (Level 1, Scorable)
Add or modify the ServerSignature directive as shown below to have the value of Off: ServerSignature Off Page 68-69</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.16 Software Information Leakage Protection p29</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27903-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache runtime rewriting engine should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) off/on</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: RewriteEngine directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.9 Restrict HTTP Protocol Versions (Level 1, Scorable)
Add the RewriteEngine directive to the configuration within the global server context with the value of on so that the rewrite engine is enabled. RewriteEngine On Page 43-44</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.11 Restrict HTTP Protocol Version p19</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27791-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache ErrorDocument directive should be set correctly for HTTP 400 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 400' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27910-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 401 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 401' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27680-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 403 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 403' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27390-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 404 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 404' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27860-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 405 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 405' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27817-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ApacheErrorDocument directive should be set correctly for HTTP 500 errors.</description>
      <parameters>
        <parameter>(1) message/document</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: 'ErrorDocument 500' directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>2.7 Additional Software Information Leakage Protection p50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27781-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache user account should be locked or unlocked as appropriate.</description>
      <parameters>
        <parameter>(1) locked/unlocked</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.3 Lock the Apache User Account (Level 1, Scorable)
Use the passwd command to lock the apache account: # passwd -l apache Page 21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27878-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Apache user account should be allowed root privileges as appropriate.</description>
      <parameters>
        <parameter>(1) allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.1 Run the Apache Web Server as a non-root user (Level 1, Scorable)
Although Apache typically is started with root privileges in order to listen on port 80 and 443, it can and should run as another non-root user in order to perform the web services. Page 19</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.6 Creating the Apache User and Group Accounts p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27722-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The group membership of the Apache user account should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via /etc/group</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.1 Run the Apache Web Server as a non-root user (Level 1, Scorable)
Although Apache typically is started with root privileges in order to listen on port 80 and 443, it can and should run as another non-root user in order to perform the web services. Page 19</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.6 Creating the Apache User and Group Accounts p14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27302-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ownership of the Apache /etc/httpd/conf/passwd file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27700-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The group membership of the Apache /etc/httpd/conf/passwd file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27837-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The permissions for the Apache /etc/httpd/conf/passwd file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27856-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ownership of the Apache /var/www/html file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27841-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The group membership of the Apache /var/www/html file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27854-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The permissions for the Apache/var/www/html file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27714-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ownership of log files in Apache /var/log/httpd/ should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.6 Core Dump Directory Security (Level 1, Scorable)
must be owned by root and have a group ownership of the Apache group (as defined via the Group directive)
# chown root:apache /var/log/httpd Page 23</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27422-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The group membership of any Apache files in /var/log/httpd/ should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.6 Core Dump Directory Security (Level 1, Scorable)
must be owned by root and have a group ownership of the Apache group (as defined via the Group directive)
# chown root:apache /var/log/httpd Page 23</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27943-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The permissions of any Apache files in /var/log/httpd/ should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.3.6 Core Dump Directory Security (Level 1, Scorable)
must have no read-write-search access permission for other users.
# chmod o-rwx /var/log/httpd Page 23</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27497-7' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ownership of the Apache /etc/httpd/conf.d file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27601-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The group membership of the Apache /etc/httpd/conf.d file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27462-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The permissions for the Apache /etc/httpd/conf.d file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27217-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ownership of the Apache /usr/sbin/httpd file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27273-2' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The group membership of the Apache /usr/sbin/httpd file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27915-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The permissions for the Apache /usr/sbin/httpd file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27935-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The ownership of the Apache /usr/sbin/apachectl file should be set correctly.</description>
      <parameters>
        <parameter>(1) owner</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-26955-5' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The group membership of the Apache /usr/sbin/apachectl file should be set correctly.</description>
      <parameters>
        <parameter>(1) group</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chgrp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27901-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The permissions for the Apache /usr/sbin/apachectl file should be set correctly.</description>
      <parameters>
        <parameter>(1) permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.19 Updating Ownership and Permissions p34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27519-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The "FollowSymLinks" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) FollowSymLinks / -FollowSymLinks / +FollowSymLinks / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.2 Restrict Options for the Web Root Directory (Level 1, Scorable)
Add or modify any existing Options directive to have a value of None or Multiviews, if multiviews are needed. Page 34</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27892-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The"Includes" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) Includes / -Includes / +Includes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.2 Restrict Options for the Web Root Directory (Level 1, Scorable)
Add or modify any existing Options directive to have a value of None or Multiviews, if multiviews are needed. Page 34</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27509-9' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The "IncludesNOEXEC" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) IncludesNoExec / -IncludesNoExec / +IncludesNoExec / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.2 Restrict Options for the Web Root Directory (Level 1, Scorable)
Add or modify any existing Options directive to have a value of None or Multiviews, if multiviews are needed. Page 34</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27382-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The "Indexes" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) Indexes / -Indexes / +Indexes / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.2 Restrict Options for the Web Root Directory (Level 1, Scorable)
Add or modify any existing Options directive to have a value of None or Multiviews, if multiviews are needed. Page 34</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27944-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The"MultiViews" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) MultiViews / -MultiViews / +MultiViews / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.2 Restrict Options for the Web Root Directory (Level 1, Scorable)
Add or modify any existing Options directive to have a value of None or Multiviews, if multiviews are needed. Page 34</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27897-8' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The "ExecCGI" setting of the DocumentRoot should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) ExecCGI / -ExecCGI/ +ExecCGI / None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Options directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.2 Restrict Options for the Web Root Directory (Level 1, Scorable)
Add or modify any existing Options directive to have a value of None or Multiviews, if multiviews are needed. Page 34</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.8 Directory Functionality Control with the Options Directive p16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27882-0' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Order directive for all DocumentRoot directives should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Allow,Deny / Deny,Allow / Mutual-failure</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Apache configuration file: Order directive (in DocumentRoot Directory directive)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.7 Limit HTTP Request Methods (Level 1, Scorable)
Search for the &lt;Directory&gt; directive on the document root directory … Ensure that the access control order within the &lt;Directory&gt; directive is allow, deny. Order allow,deny Page 41</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27313-6' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Order directive for the specified Directory directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Allow,Deny / Deny,Allow / Mutual-failure</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) TARGET: Directory directive</technical_mechanism>
        <technical_mechanism>(2) Apache configuration file: Order directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.4.2 Allow Appropriate Access to Web Content (Level 1, Not Scorable)
Search the Apache configuration files (httpd.conf and any included configuration files) to find all &lt;Directory&gt; and &lt;Location&gt; elements … Add a single Order directive and set the value to deny, allow. Page 28-29</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-26965-4' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Allow directive for the specified Directory directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Allow directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.4.2 Allow Appropriate Access to Web Content (Level 1, Not Scorable)
Search the Apache configuration files (httpd.conf and any included configuration files) to find all &lt;Directory&gt; and &lt;Location&gt; elements … Include the appropriate Allow and Deny directives, with values that are appropriate for the purposes of the directory. Page 28-29</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p14-15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27023-1' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>The Deny directive for the specified Directory directive should be configured appropriately.</description>
      <parameters>
        <parameter>(1) all | hostname/IP address/environment variable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Deny directive</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.4.2 Allow Appropriate Access to Web Content (Level 1, Not Scorable)
Search the Apache configuration files (httpd.conf and any included configuration files) to find all &lt;Directory&gt; and &lt;Location&gt; elements … Include the appropriate Allow and Deny directives, with values that are appropriate for the purposes of the directory. Page 28-29</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.7 Restricting Access p14-15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-27913-3' platform='apache-httpd2.2' modified='2013-02-11'>
      <description>testcgi should be installed as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) cgi-script directory</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2 Version 3.1.0 June 11th, 2012'>1.5.6 Remove Default CGI Content test-cgi (Level 1, Scorable)
Remove the test-cgi default CGI in cgi-bin directory if it is installed. # rm $APACHE_PREFIX/cgi-bin/test-cgi Page 39-40</reference>
        <reference resource_id='CIS Security Configuration Benchmark For Apache Web Server 2.2.0 Version 2.2.0 November 2008'>1.18 Remove Default Content p33</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19088-4' platform='exchange2007' modified='2012-02-24'>
      <description>The "Allow basic authentication" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AllowBasicAuthentication |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19184-1' platform='exchange2007' modified='2012-02-24'>
      <description>The "Allow simple passwords" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AllowSimplePasswords |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19107-2' platform='exchange2007' modified='2012-02-24'>
      <description>The "Allow unmanaged devices" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AllowUnmanagedDevices |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19178-3' platform='exchange2007' modified='2012-02-24'>
      <description>The "Configure dial plan security" setting should be configured correctly.</description>
      <parameters>
        <parameter>Unsecured, SIPSecured, Secured</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType DialPlanSecure |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19098-3' platform='exchange2007' modified='2012-02-24'>
      <description>The "Configure login authentication for IMAP4" setting should be configured correctly.</description>
      <parameters>
        <parameter>PlainTextLogin, PlainTextAuthentication, SecureLogin</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType IMAP4LoginType |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18657-7' platform='exchange2007' modified='2012-02-24'>
      <description>The "Configure login authentication for POP3" setting should be configured correctly.</description>
      <parameters>
        <parameter>PlainTextLogin, PlainTextAuthentication, SecureLogin</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType POP3LoginType |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19200-5' platform='exchange2007' modified='2012-02-24'>
      <description>The "Configure Protocol logging" setting should be configured correctly.</description>
      <parameters>
        <parameter>Verbose, None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ProtocolLogging |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18409-3' platform='exchange2007' modified='2012-02-24'>
      <description>The "Configure Sender Filtering" setting should be configured correctly.</description>
      <parameters>
        <parameter>StampStatus, Reject</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType SenderFiltering |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19203-9' platform='exchange2007' modified='2012-02-24'>
      <description>The "Do not permamently delete items until the database has been backed up" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RetainDeletedItemsUntilBackup |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19015-7' platform='exchange2007' modified='2012-02-24'>
      <description>The "Enable automatic forwards to remote domains" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AutomaticForwardsRemoteDomains |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19198-1' platform='exchange2007' modified='2012-02-24'>
      <description>The "Enable automatic replies to remote domains" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AutomaticRepliesRemoteDomains |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19207-0' platform='exchange2007' modified='2012-02-24'>
      <description>The "Enable non-delivery reports to remote domains" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType NonDeliveryReportsRemoteDomains |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19191-6' platform='exchange2007' modified='2012-02-24'>
      <description>The "Enable OOF messages to remote domains" setting should be configured correctly.</description>
      <parameters>
        <parameter>External, ExternalLegacy, None, and InternalLegacy</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType OofMessagesRemoteDomains |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18405-1' platform='exchange2007' modified='2012-02-24'>
      <description>The "Enable S/MIME for OWA 2007" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType SMimeEnabled2007 |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19150-2' platform='exchange2007' modified='2012-02-24'>
      <description>The "Enable Sender ID agent" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType SenderID |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19035-5' platform='exchange2007' modified='2012-02-24'>
      <description>The "Enable Sender Reputation" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType SenderReputation |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19205-4' platform='exchange2007' modified='2012-02-24'>
      <description>The "Enforce Password History" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 50 passwords</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType EnforcePasswordHistory |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19116-3' platform='exchange2007' modified='2012-02-24'>
      <description>The "External send connector authentication: DNS Routing" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ExternalSendConnectorAuthDNSRoutingEnabled |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19112-2' platform='exchange2007' modified='2012-02-24'>
      <description>The "External send connector authentication: Domain Security" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ExternalSendConnectorAuthDomainSecureEnabled |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18256-8' platform='exchange2007' modified='2012-02-24'>
      <description>The "External send connector authentication: Ignore Start TLS" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ExternalSendConnectorAuthIgnoreSTARTTLS |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19188-2' platform='exchange2007' modified='2012-02-24'>
      <description>The "Keep deleted mailboxes for the specified number of days" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 24855 Days</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType KeepDeletedMailboxes |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19239-3' platform='exchange2007' modified='2012-02-24'>
      <description>The "Mailbox quotas: Issue warning at" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2147483647 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MailboxApproachingStorageLimitWarning |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19195-7' platform='exchange2007' modified='2012-02-24'>
      <description>The "Mailbox quotas: Prohibit send and receive at" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2147483647 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ProhibitSendReceiveQuota |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18295-6' platform='exchange2007' modified='2012-02-24'>
      <description>The "Mailbox quotas: Prohibit send at" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2147483647 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ProhibitSendQuota |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18314-5' platform='exchange2007' modified='2012-02-24'>
      <description>The "Maximum number of recipients - organization level" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2147483647 recipients</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaximumNumberRecipients |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18897-9' platform='exchange2007' modified='2012-02-24'>
      <description>The "Maximum receive size - connector level" setting should be configured correctly.</description>
      <parameters>
        <parameter>64 - 2147483647 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaximumReceiveSizeConnector |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19036-3' platform='exchange2007' modified='2012-02-24'>
      <description>The "Maximum receive size - organization level" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2097151 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaximumReceiveSizeOrganization |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18354-1' platform='exchange2007' modified='2012-02-24'>
      <description>The "Maximum send size - connector level" setting should be configured correctly.</description>
      <parameters>
        <parameter>64 - 2147483647 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaximumSendSizeConnector |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19165-0' platform='exchange2007' modified='2012-02-24'>
      <description>The "Maximum send size - organization level" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2097151 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaximumSendSizeOrganization |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18561-1' platform='exchange2007' modified='2012-02-24'>
      <description>The "Message tracking logging - Mailbox" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MessageTrackingLoggingMailbox |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19093-4' platform='exchange2007' modified='2012-02-24'>
      <description>The "Message tracking logging - Transport" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MessageTrackingLoggingTransport |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19329-2' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Active Directory Topology" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Active Directory Topology </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeADTopology\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19214-6' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange ADAM" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange ADAM </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ADAM_MSExchange\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19294-8' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Anti-spam Update" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Anti-spam Update</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeAntispamUpdate\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19174-2' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Credential Service (Exchange 2007)" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Credential Service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\EdgeCredentialSvc\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19234-4' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange EdgeSync Service" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange EdgeSync Service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeEdgeSync\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19213-8' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange File Distribution" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange File Distribution </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeFDS\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19155-1' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange IMAP4" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange IMAP4 </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeIMAP4\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19120-5' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Information Store" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Information Store </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeIS\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19268-2' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Mail Submission Service" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Mail Submission Service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeMailSubmission\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19193-2' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Mailbox Assistants" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Mailbox Assistants </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeMailboxAssistants\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19171-8' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Monitoring" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Monitoring </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeMonitoring\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19108-0' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange POP3" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange POP3 </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangePOP3\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19334-2' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Replication Service" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Replication Service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeRepl\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19243-5' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Search Indexer" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Search Indexer </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeSearch\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19139-5' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Server Extension for Windows Server Backup" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Server Extension for Windows Server Backup </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wsbexchange\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19144-5' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Service Host" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Service Host </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeServiceHost\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19134-6' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Speech Engine Service" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Speech Engine Service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSSpeechService\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18914-2' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange System Attendant" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange System Attendant </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeSA\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19020-7' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Transport" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Transport </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeTransport\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19303-7' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Transport Log Search" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Transport Log Search </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeTransportLogSearch\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19008-2' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Unified Messaging" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Unified Messaging </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeUM\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19055-3' platform='exchange2007' modified='2012-02-24'>
      <description>The machine setting for the startup type of the "Microsoft Search (Exchange)" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Search (Exchange) </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\msftesql-Exchange\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19185-8' platform='exchange2007' modified='2012-02-24'>
      <description>The "Minimum password length" setting should be configured correctly.</description>
      <parameters>
        <parameter>1 - 16</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MinimumPasswordLength |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19054-6' platform='exchange2007' modified='2012-02-24'>
      <description>The "Mount database at startup" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MountDatabaseAtStartup |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19310-2' platform='exchange2007' modified='2012-02-24'>
      <description>The "Number of attempts allowed" setting should be configured correctly.</description>
      <parameters>
        <parameter>4 - 16 Attempts</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType NumberAttemptsAllowed |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19349-0' platform='exchange2007' modified='2012-02-24'>
      <description>The "Password Expiration" setting should be configured correctly.</description>
      <parameters>
        <parameter>1:00:00:00 - 730:00:00:00 Days</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType PasswordExpiration |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19264-1' platform='exchange2007' modified='2012-02-24'>
      <description>The "Refresh interval" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 596523 Hours</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RefreshInterval |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19149-4' platform='exchange2007' modified='2012-02-24'>
      <description>The "Require alphanumeric password" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RequireAlphanumericPassword |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19251-8' platform='exchange2007' modified='2012-02-24'>
      <description>The "Require Client Certificates" setting should be configured correctly.</description>
      <parameters>
        <parameter>Ignore, Accepted, or Required</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RequireClientCertificates |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19351-6' platform='exchange2007' modified='2012-02-24'>
      <description>The "Require encryption on device" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RequireEncryptionOnDevice |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19194-0' platform='exchange2007' modified='2012-02-24'>
      <description>The "Require password" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RequirePassword |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19285-6' platform='exchange2007' modified='2012-02-24'>
      <description>The "Retain deleted items for the specified number of days" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 30 Days</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType DeletedItemRetention |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19280-7' platform='exchange2007' modified='2012-02-24'>
      <description>The "Time without user input before password must be re-entered" setting should be configured correctly.</description>
      <parameters>
        <parameter>1 - 60 Minutes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaxInactivityTimeDeviceLock |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19339-1' platform='exchange2007' modified='2012-02-24'>
      <description>The "Turn on Connectivity logging" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ConnectivityLogging |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19327-6' platform='exchange2007' modified='2012-02-24'>
      <description>The "Turn on script execution" setting should be configured correctly.</description>
      <parameters>
        <parameter>Restricted/ AllSigned/ RemoteSigned/ Unrestricted</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ExecutionPolicy |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2007 SP3 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19141-1' platform='exchange2010' modified='2012-03-12'>
      <description>The "Allow access to voicemail without requiring a PIN" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType PinlessAccessToVoicemail |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19132-0' platform='exchange2010' modified='2012-03-12'>
      <description>The "Allow basic authentication" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AllowBasicAuthentication |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18357-4' platform='exchange2010' modified='2012-03-12'>
      <description>The "Allow simple passwords" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AllowSimplePasswords |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18866-4' platform='exchange2010' modified='2012-03-12'>
      <description>The "Allow unmanaged devices" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AllowUnmanagedDevices |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19115-5' platform='exchange2010' modified='2012-03-12'>
      <description>The "Configure dial plan security" setting should be configured correctly.</description>
      <parameters>
        <parameter>Unsecured, SIPSecured, Secured</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType DialPlanSecure |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18176-8' platform='exchange2010' modified='2012-03-12'>
      <description>The "Configure login authentication for IMAP4" setting should be configured correctly.</description>
      <parameters>
        <parameter>PlainTextLogin, PlainTextAuthentication, SecureLogin</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType IMAP4LoginType |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19077-7' platform='exchange2010' modified='2012-03-12'>
      <description>The "Configure login authentication for POP3" setting should be configured correctly.</description>
      <parameters>
        <parameter>PlainTextLogin, PlainTextAuthentication, SecureLogin</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType POP3LoginType |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18924-1' platform='exchange2010' modified='2012-03-12'>
      <description>The "Configure Protocol logging" setting should be configured correctly.</description>
      <parameters>
        <parameter>Verbose, None</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ProtocolLogging |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18693-2' platform='exchange2010' modified='2012-03-12'>
      <description>The "Configure Sender Filtering" setting should be configured correctly.</description>
      <parameters>
        <parameter>StampStatus, Reject</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType SenderFiltering |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18710-4' platform='exchange2010' modified='2012-03-12'>
      <description>The "Configure startup mode" setting should be configured correctly.</description>
      <parameters>
        <parameter>TCP, Dual, TLS</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType UMStartupMode |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18273-3' platform='exchange2010' modified='2012-03-12'>
      <description>The "Do not permamently delete items until the database has been backed up" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RetainDeletedItemsUntilBackup |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18842-5' platform='exchange2010' modified='2012-03-12'>
      <description>The "Enable automatic forwards to remote domains" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AutomaticForwardsRemoteDomains |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19131-2' platform='exchange2010' modified='2012-03-12'>
      <description>The "Enable automatic replies to remote domains" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AutomaticRepliesRemoteDomains |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19057-9' platform='exchange2010' modified='2012-03-12'>
      <description>The "Enable non-delivery reports to remote domains" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType NonDeliveryReportsRemoteDomains |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19022-3' platform='exchange2010' modified='2012-03-12'>
      <description>The "Enable OOF messages to remote domains" setting should be configured correctly.</description>
      <parameters>
        <parameter>External, ExternalLegacy, None, and InternalLegacy</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType OofMessagesRemoteDomains |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19096-7' platform='exchange2010' modified='2012-03-12'>
      <description>The "Enable S/MIME for OWA 2010" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType SMimeEnabled2010 |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18208-9' platform='exchange2010' modified='2012-03-12'>
      <description>The "Enable Sender ID agent" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType SenderID |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18326-9' platform='exchange2010' modified='2012-03-12'>
      <description>The "Enable Sender Reputation" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType SenderReputation |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19013-2' platform='exchange2010' modified='2012-03-12'>
      <description>The "Enforce Password History" setting should be configured correctly.</description>
      <parameters>
        <parameter>0-50 passwords</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType EnforcePasswordHistory |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19081-9' platform='exchange2010' modified='2012-03-12'>
      <description>The "External send connector authentication: DNS Routing" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ExternalSendConnectorAuthDNSRoutingEnabled |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18182-6' platform='exchange2010' modified='2012-03-12'>
      <description>The "External send connector authentication: Domain Security" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ExternalSendConnectorAuthDomainSecureEnabled |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18214-7' platform='exchange2010' modified='2012-03-12'>
      <description>The "External send connector authentication: Ignore Start TLS" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ExternalSendConnectorAuthIgnoreSTARTTLS |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19076-9' platform='exchange2010' modified='2012-03-12'>
      <description>The "Keep deleted mailboxes for the specified number of days" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 24855 days</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType KeepDeletedMailboxes |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18662-7' platform='exchange2010' modified='2012-03-12'>
      <description>The "Mailbox quotas: Issue warning at" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2147483647 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MailboxApproachingStorageLimitWarning |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18281-6' platform='exchange2010' modified='2012-03-12'>
      <description>The "Mailbox quotas: Prohibit send and receive at" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2147483647 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ProhibitSendReceiveQuota |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18515-7' platform='exchange2010' modified='2012-03-12'>
      <description>The "Mailbox quotas: Prohibit send at" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2147483647 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ProhibitSendQuota |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18506-6' platform='exchange2010' modified='2012-03-12'>
      <description>The "Maximum number of recipients - organization level" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2147483647 recipients</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaximumNumberRecipients |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19113-0' platform='exchange2010' modified='2012-03-12'>
      <description>The "Maximum receive size - connector level" setting should be configured correctly.</description>
      <parameters>
        <parameter>64 - 2147483647 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaximumReceiveSizeConnector |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19010-8' platform='exchange2010' modified='2012-03-12'>
      <description>The "Maximum receive size - organization level" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2097151 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaximumReceiveSizeOrganization |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18590-0' platform='exchange2010' modified='2012-03-12'>
      <description>The "Maximum send size - connector level" setting should be configured correctly.</description>
      <parameters>
        <parameter>64 - 2147483647 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaximumSendSizeConnector |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19156-9' platform='exchange2010' modified='2012-03-12'>
      <description>The "Maximum send size - organization level" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 2097151 KB</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaximumSendSizeOrganization |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18647-8' platform='exchange2010' modified='2012-03-12'>
      <description>The "Message tracking logging - Mailbox" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MessageTrackingLoggingMailbox |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19094-2' platform='exchange2010' modified='2012-03-12'>
      <description>The "Message tracking logging - Transport" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MessageTrackingLoggingTransport |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18530-6' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Active Directory Topology" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Active Directory Topology </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeADTopology\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19176-7' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange ADAM" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange ADAM </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ADAM_MSExchange\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18189-1' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Address Book" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Address Book</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeAB\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19179-1' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Anti-spam Update" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Anti-spam Update</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeAntispamUpdate\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19126-2' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Credential Service (Exchange 2010)" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Credential Service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeEdgeCredential\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19164-3' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange EdgeSync Service" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange EdgeSync Service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeEdgeSync\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18421-8' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange File Distribution" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange File Distribution </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeFDS\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19181-7' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Forms-Based Authentication service" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Forms-Based Authentication service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeFBA\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18945-6' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange IMAP4" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange IMAP4 </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeIMAP4\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18199-0' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Information Store" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Information Store </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeIS\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18635-3' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Mail Submission Service" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Mail Submission Service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeMailSubmission\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19083-5' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Mailbox Assistants" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Mailbox Assistants </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeMailboxAssistants\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19066-0' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Mailbox Replication" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Mailbox Replication </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeMailboxReplication\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19100-7' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Monitoring" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Monitoring </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeMonitoring\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18778-1' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange POP3" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange POP3 </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangePOP3\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18352-5' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Protected Service Host" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Protected Service Host </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeProtectedServiceHost\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18595-9' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Replication Service" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Replication Service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeRepl\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19101-5' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange RPC Client Access" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange RPC Client Access </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeRPC\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19031-4' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Search Indexer" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Search Indexer </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeSearch\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18203-0' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Server Extension for Windows Server Backup" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Server Extension for Windows Server Backup </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wsbexchange\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19109-8' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Service Host" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Service Host </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeServiceHost\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19136-1' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Speech Engine Service" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Speech Engine Service </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSSpeechService\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18212-1' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange System Attendant" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange System Attendant </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeSA\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19201-3' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Throttling" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Throttling </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeThrottling\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18234-5' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Transport" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Transport </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeTransport\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19208-8' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Transport Log Search" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Transport Log Search </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeTransportLogSearch\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19121-3' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Exchange Unified Messaging" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Exchange Unified Messaging </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\MSExchangeUM\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18373-1' platform='exchange2010' modified='2012-03-12'>
      <description>The machine setting for the startup type of the "Microsoft Search (Exchange)" service should be configured correctly.</description>
      <parameters>
        <parameter>Automatic = 2, Manual=3, Disabled=4</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Windows Settings\Security Settings\System Services\Microsoft Search (Exchange) </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\msftesql-Exchange\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18241-0' platform='exchange2010' modified='2012-03-12'>
      <description>The "Minimum password length" setting should be configured correctly.</description>
      <parameters>
        <parameter>1 to 16 characters</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MinimumPasswordLength |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19042-1' platform='exchange2010' modified='2012-03-12'>
      <description>The "Mount database at startup" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MountDatabaseAtStartup |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19190-8' platform='exchange2010' modified='2012-03-12'>
      <description>The "Number of attempts allowed" setting should be configured correctly.</description>
      <parameters>
        <parameter>4 - 16 Attempts</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType NumberAttemptsAllowed |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19215-3' platform='exchange2010' modified='2012-03-12'>
      <description>The "Password Expiration" setting should be configured correctly.</description>
      <parameters>
        <parameter>1:00:00:00 - 730:00:00:00 Days</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType PasswordExpiration |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19091-8' platform='exchange2010' modified='2012-03-12'>
      <description>The "Refresh interval" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 596523 Hours</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RefreshInterval |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19177-5' platform='exchange2010' modified='2012-03-12'>
      <description>The "Require alphanumeric password" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RequireAlphanumericPassword |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19221-1' platform='exchange2010' modified='2012-03-12'>
      <description>The "Require Client Certificates" setting should be configured correctly.</description>
      <parameters>
        <parameter>Ignore, Accepted, or Required</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RequireClientCertificates |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18242-8' platform='exchange2010' modified='2012-03-12'>
      <description>The "Require client MAPI encryption" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RequireClientMAPIEncryption |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19202-1' platform='exchange2010' modified='2012-03-12'>
      <description>The "Require encryption on device" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RequireEncryptionOnDevice |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19162-7' platform='exchange2010' modified='2012-03-12'>
      <description>The "Require password" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType RequirePassword |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19241-9' platform='exchange2010' modified='2012-03-12'>
      <description>The "Retain deleted items for the specified number of days" setting should be configured correctly.</description>
      <parameters>
        <parameter>0 - 30 Days</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType DeletedItemRetention |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18432-5' platform='exchange2010' modified='2012-03-12'>
      <description>The "Time without user input before password must be re-entered" setting should be configured correctly.</description>
      <parameters>
        <parameter>1 - 60 Minutes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType MaxInactivityTimeDeviceLock |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19153-6' platform='exchange2010' modified='2012-03-12'>
      <description>The "Turn on Administrator Audit Logging" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType AdministratorAuditLogging |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19219-5' platform='exchange2010' modified='2012-03-12'>
      <description>The "Turn on Connectivity logging" setting should be configured correctly.</description>
      <parameters>
        <parameter>True/False</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ConnectivityLogging |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19240-1' platform='exchange2010' modified='2012-03-12'>
      <description>The "Turn on script execution" setting should be configured correctly.</description>
      <parameters>
        <parameter>Restricted/ AllSigned/ RemoteSigned/ Unrestricted</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Powershell: Get-ExchangeConfiguration -configType ExecutionPolicy |Select-Object -Property SettingData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Exchange Server 2010 SP2 1.0
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940

Note, use SCM global search and baseline filter to locate settings related to CCE ID</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5435-3' platform='hpux11.23' modified='2009-04-30'>
      <description>/export/home should be configured on an appropriate filesystem logical volume</description>
      <parameters>
        <parameter>logical volume</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via fstab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.2.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6030-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/var should be configured on an appropriate filesystem logical volume</description>
      <parameters>
        <parameter>logical volume</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via fstab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.2.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5936-0' platform='hpux11.23' modified='2009-04-30'>
      <description>/opt should be configured on an appropriate filesystem logical volume</description>
      <parameters>
        <parameter>logical volume</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via fstab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.2.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6122-6' platform='hpux11.23' modified='2009-04-30'>
      <description>The shell for the root account should be located on the appropriate filesystem</description>
      <parameters>
        <parameter>filesystem</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.2.1 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6091-3' platform='hpux11.23' modified='2009-04-30'>
      <description>Core dump size limits should be set appropriately</description>
      <parameters>
        <parameter>Size (0 to disable core dumps)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/limits</technical_mechanism>
        <technical_mechanism>via ulimit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.4 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6249-7' platform='hpux11.23' modified='2009-04-30'>
      <description>The read-only SNMP community string should be set appropriately.</description>
      <parameters>
        <parameter>string</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/snmp.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (1) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6095-4' platform='hpux11.23' modified='2009-04-30'>
      <description>The read/write SNMP community string should be set appropriately.</description>
      <parameters>
        <parameter>string</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/snmp.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (1) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6108-5' platform='hpux11.23' modified='2009-04-30'>
      <description>Password policy should ban or allow usernames or UIDs in passwords as appropriate</description>
      <parameters>
        <parameter>ban/allow</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5812-3' platform='hpux11.23' modified='2009-04-30'>
      <description>Password policy should ban or allow words found in a dictionary as appropriate.</description>
      <parameters>
        <parameter>ban/allow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6161-4' platform='hpux11.23' modified='2009-04-30'>
      <description>Password policy should enforce the correct amount of special characters</description>
      <parameters>
        <parameter>number of special characters</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6172-1' platform='hpux11.23' modified='2009-04-30'>
      <description>Password policy should enforce or not enforce the requirement to have mixed case passwords as appropriate.</description>
      <parameters>
        <parameter>enforce/not enforce</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5639-0' platform='hpux11.23' modified='2009-04-30'>
      <description>The minimum password age should be set as appropriate</description>
      <parameters>
        <parameter>number of days</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6163-0' platform='hpux11.23' modified='2009-04-30'>
      <description>The minimum required password length should be set as appropriate</description>
      <parameters>
        <parameter>number of characters</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5982-4' platform='hpux11.23' modified='2009-04-30'>
      <description>Password history should be saved for an appropriate number of password changes</description>
      <parameters>
        <parameter>number of password changes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) d)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5956-8' platform='hpux11.23' modified='2009-04-30'>
      <description>The number of consecutive failed login attempts required to trigger a lockout should be set as appropriate</description>
      <parameters>
        <parameter>number of consecutive failed login attempts</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/user</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) e)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6219-0' platform='hpux11.23' modified='2009-04-30'>
      <description>Login access to accounts without passwords should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via passwd</technical_mechanism>
        <technical_mechanism>via /etc/shadow</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5925-3' platform='hpux11.23' modified='2009-04-30'>
      <description>New users should be required or not required to change their password on first login as appropriate</description>
      <parameters>
        <parameter>required/not required</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (2) g)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6140-8' platform='hpux11.23' modified='2009-04-30'>
      <description>Access to single-user mode (maintainence mode) should require the root password or not as appropriate</description>
      <parameters>
        <parameter>required/not required</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6180-4' platform='hpux11.23' modified='2009-04-30'>
      <description>The delay between failed logins should be set as appropriate</description>
      <parameters>
        <parameter>number of seconds</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6114-3' platform='hpux11.23' modified='2009-04-30'>
      <description>All files should be owned by an existing account or not as appropriate.</description>
      <parameters>
        <parameter>existing account required / existing account not required</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6120-0' platform='hpux11.23' modified='2009-04-30'>
      <description>All files should be owned by an existing group or not as appropriate.</description>
      <parameters>
        <parameter>existing group required / existing group not required</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6094-7' platform='hpux11.23' modified='2009-04-30'>
      <description>The console login banner should be set appropriately.</description>
      <parameters>
        <parameter>banner text or null</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/login.cfg</technical_mechanism>
        <technical_mechanism>via /etc/motd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (5) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5561-6' platform='hpux11.23' modified='2009-04-30'>
      <description>The SSH login banner should be set appropriately.</description>
      <parameters>
        <parameter>banner text or null</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via sshd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (5) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5583-0' platform='hpux11.23' modified='2009-04-30'>
      <description>The telnet login banner should be set appropriately.</description>
      <parameters>
        <parameter>banner text or null</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via telnetd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (5) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5552-5' platform='hpux11.23' modified='2009-04-30'>
      <description>The ftp login banner should be set appropriately.</description>
      <parameters>
        <parameter>banner text or null</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (5) d)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5255-5' platform='hpux11.23' modified='2009-04-30'>
      <description>The graphical login banner should be set appropriately.</description>
      <parameters>
        <parameter>banner text or null</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via Xwindows</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2 (5) e)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6043-4' platform='hpux11.23' modified='2009-04-30'>
      <description>Accounts other than root should be allowed to have the UID 0 or not as appropriate</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via passwd</technical_mechanism>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.1 (2) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6117-6' platform='hpux11.23' modified='2009-04-30'>
      <description>Accounts other than root and locked system accounts should be allowed to have a GID of 0 or not as appropriate</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via passwd</technical_mechanism>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.1 (2) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5883-4' platform='hpux11.23' modified='2009-04-30'>
      <description>Each account should be assigned a unique UID or not as appropriate</description>
      <parameters>
        <parameter>unique/not unique</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.4 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5261-3' platform='hpux11.23' modified='2009-04-30'>
      <description>The ftp account should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.4 (9)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5495-7' platform='hpux11.23' modified='2009-04-30'>
      <description>Login accounts should include an appropriate GECOS identifier or no GECOS identifier</description>
      <parameters>
        <parameter>GECOS value, null</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.4.1 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5949-3' platform='hpux11.23' modified='2009-04-30'>
      <description>The screen lock should activate after an appropriate period of inactivity</description>
      <parameters>
        <parameter>number of minutes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via Xscreensaver</technical_mechanism>
        <technical_mechanism>via dtsession</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.5 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6147-3' platform='hpux11.23' modified='2009-04-30'>
      <description>File permissions should be set appropriately for all shell executables.</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6182-0' platform='hpux11.23' modified='2009-04-30'>
      <description>Remote (serial) consoles should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inittab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5764-6' platform='hpux11.23' modified='2009-04-30'>
      <description>Root logins should be restricted to the console or not as appropriate.</description>
      <parameters>
        <parameter>restricted/not restricted</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (4)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6151-5' platform='hpux11.23' modified='2009-04-30'>
      <description>.netrc files should exist or not as appropriate for all users.</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5516-0' platform='hpux11.23' modified='2009-04-30'>
      <description>.rhosts files should exist or not as appropriate for all users.</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6089-7' platform='hpux11.23' modified='2009-04-30'>
      <description>.shosts files should exist or not as appropriate for all users.</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5873-5' platform='hpux11.23' modified='2009-04-30'>
      <description>The /etc/hosts.equiv file should exist or not as appropriate.</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (6)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6186-1' platform='hpux11.23' modified='2009-04-30'>
      <description>The /etc/shells file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/shells</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (11)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6191-1' platform='hpux11.23' modified='2009-04-30'>
      <description>Shells referenced in /etc/passwd should be included in /etc/shells or not as appropriate</description>
      <parameters>
        <parameter>included/not included</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/shells</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (12)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-8640-5' platform='hpux11.23' modified='2009-04-30'>
      <description>The use of NIS special characters  (+ or -) in the first field of the /etc/passwd file should be allowed or disallowed as appropriate.</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via Text editor</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (7)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-8240-4' platform='hpux11.23' modified='2009-04-30'>
      <description>The use of NIS special characters  (+ or -) in the first field of the /etc/shadow file should be allowed or disallowed as appropriate.</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via Text editor</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (7)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-8631-4' platform='hpux11.23' modified='2009-04-30'>
      <description>The use of NIS special characters  (+ or -) in the first field of the /etc/group file should be allowed or disallowed as appropriate.</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via Text editor</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (7)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6208-3' platform='hpux11.23' modified='2009-04-30'>
      <description>Groups referenced in /etc/passwd should be included in /etc/group or not as appropriate.</description>
      <parameters>
        <parameter>included/not included</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/group</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (15)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5265-4' platform='hpux11.23' modified='2009-04-30'>
      <description>The home directory for the root account should be set appropriately.</description>
      <parameters>
        <parameter>path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (16)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6133-3' platform='hpux11.23' modified='2009-04-30'>
      <description>The home directory for each user account should be set appropriately.</description>
      <parameters>
        <parameter>path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/passwd</technical_mechanism>
        <technical_mechanism>via /usr/sbin/useradd</technical_mechanism>
        <technical_mechanism>via /etc/default/useradd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (17)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5797-6' platform='hpux11.23' modified='2009-04-30'>
      <description>Home directories referenced in /etc/passwd should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (18)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5886-7' platform='hpux11.23' modified='2009-04-30'>
      <description>All device files should be located inside an appropriate path</description>
      <parameters>
        <parameter>path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (24)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5762-0' platform='hpux11.23' modified='2009-04-30'>
      <description>The ntpd service should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.3 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5987-3' platform='hpux11.23' modified='2009-04-30'>
      <description>The Network Time Protocol (ntp) synchronization server should be set appropriately.</description>
      <parameters>
        <parameter>timeserver</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via ntpd.conf</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-5828-9' platform='hpux11.23' modified='2009-04-30'>
      <description>The default gateway should be set appropriately.</description>
      <parameters>
        <parameter>IP address/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/default/route.conf</technical_mechanism>
        <technical_mechanism>via /etc/gated.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (4)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5927-9' platform='hpux11.23' modified='2009-04-30'>
      <description>The inetd service should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6143-2' platform='hpux11.23' modified='2009-04-30'>
      <description>echo service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6054-1' platform='hpux11.23' modified='2009-04-30'>
      <description>netstat service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6010-3' platform='hpux11.23' modified='2009-04-30'>
      <description>rcp service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #3</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5460-1' platform='hpux11.23' modified='2009-04-30'>
      <description>chargen service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5618-4' platform='hpux11.23' modified='2009-04-30'>
      <description>finger service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5838-8' platform='hpux11.23' modified='2009-04-30'>
      <description>tftpd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5878-4' platform='hpux11.23' modified='2009-04-30'>
      <description>walld service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #7</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5266-2' platform='hpux11.23' modified='2009-04-30'>
      <description>rstatd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #8</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6138-2' platform='hpux11.23' modified='2009-04-30'>
      <description>sprayd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6057-4' platform='hpux11.23' modified='2009-04-30'>
      <description>rusersd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5885-9' platform='hpux11.23' modified='2009-04-30'>
      <description>rlogin service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5978-2' platform='hpux11.23' modified='2009-04-30'>
      <description>rsh service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5607-7' platform='hpux11.23' modified='2009-04-30'>
      <description>ftp service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6075-6' platform='hpux11.23' modified='2009-04-30'>
      <description>telnet service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6232-3' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-6171-3' platform='hpux11.23' modified='2009-04-30'>
      <description>inn service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5638-2' platform='hpux11.23' modified='2009-04-30'>
      <description>uucp service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #17</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6175-4' platform='hpux11.23' modified='2009-04-30'>
      <description>rexec service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #18</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6144-0' platform='hpux11.23' modified='2009-04-30'>
      <description>font-service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #20</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5763-8' platform='hpux11.23' modified='2009-04-30'>
      <description>imap2 service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5856-0' platform='hpux11.23' modified='2009-04-30'>
      <description>pop3 service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #22</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6081-4' platform='hpux11.23' modified='2009-04-30'>
      <description>ident service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #23</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6093-9' platform='hpux11.23' modified='2009-04-30'>
      <description>rexd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6173-9' platform='hpux11.23' modified='2009-04-30'>
      <description>daytime service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #26</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5287-8' platform='hpux11.23' modified='2009-04-30'>
      <description>dtspc (cde-spc) service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6070-7' platform='hpux11.23' modified='2009-04-30'>
      <description>rquotad service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #28</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6026-9' platform='hpux11.23' modified='2009-04-30'>
      <description>cmsd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #29</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6166-3' platform='hpux11.23' modified='2009-04-30'>
      <description>tooltalk service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #30</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5867-7' platform='hpux11.23' modified='2009-04-30'>
      <description>xdmcp service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #31</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5810-7' platform='hpux11.23' modified='2009-04-30'>
      <description>discard service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #32</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5898-2' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5713-3' platform='hpux11.23' modified='2009-04-30'>
      <description>vino-server service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1 (11) #34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5994-9' platform='hpux11.23' modified='2009-04-30'>
      <description>The bind service should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via inetd.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.1 (2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6215-8' platform='hpux11.23' modified='2009-04-30'>
      <description>The version string reported by the bind service should be configured appropriately.</description>
      <parameters>
        <parameter>string</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/named.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.1 (5)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5937-8' platform='hpux11.23' modified='2009-04-30'>
      <description>The nfsd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5303-3' platform='hpux11.23' modified='2009-04-30'>
      <description>The mountd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6223-2' platform='hpux11.23' modified='2009-04-30'>
      <description>The statd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6069-9' platform='hpux11.23' modified='2009-04-30'>
      <description>The lockd service should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5320-7' platform='hpux11.23' modified='2009-04-30'>
      <description>NFS should be configured with appropriate authentication methods</description>
      <parameters>
        <parameter>list of auth methods</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via NFSvia</technical_mechanism>
        <technical_mechanism>via /etc/exports</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5593-9' platform='hpux11.23' modified='2009-04-30'>
      <description>The read-only (ro) option should be enabled or disabled as appropriate for all NFS exports.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/exports</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) g)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6256-2' platform='hpux11.23' modified='2009-04-30'>
      <description>The nosuid option should be enabled or disabled for all NFS mounts as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/fstab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) i)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5596-2' platform='hpux11.23' modified='2009-04-30'>
      <description>The nosgid option should be enabled or disabled for all NFS mounts as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/fstab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.1.5 (1) i)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6234-9' platform='hpux11.23' modified='2009-04-30'>
      <description>Sendmail should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via inetd</technical_mechanism>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6185-3' platform='hpux11.23' modified='2009-04-30'>
      <description>The sendmail banner should be set appropriately.</description>
      <parameters>
        <parameter>string</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/mail/sendmail.cf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6000-4' platform='hpux11.23' modified='2009-04-30'>
      <description>The decode sendmail alias should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/aliases</technical_mechanism>
        <technical_mechanism>via /usr/lib/aliases</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5551-7' platform='hpux11.23' modified='2009-04-30'>
      <description>.forward files should be allowed or disallowed as appropriate for all users</description>
      <parameters>
        <parameter>allow/disallow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via rm</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) e)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6018-6' platform='hpux11.23' modified='2009-04-30'>
      <description>Programs executed through the aliases file should be owned by an appropriate user</description>
      <parameters>
        <parameter>user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6141-6' platform='hpux11.23' modified='2009-04-30'>
      <description>Programs executed through the aliases file should reside a directory with an appropriate user owner</description>
      <parameters>
        <parameter>user</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6233-1' platform='hpux11.23' modified='2009-04-30'>
      <description>Sendmail vrfy command should be allowed or not as appropriate</description>
      <parameters>
        <parameter>allow/disallow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/mail/sendmail.cf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) g)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5288-6' platform='hpux11.23' modified='2009-04-30'>
      <description>Sendmail expn command should be allowed or not as appropriate</description>
      <parameters>
        <parameter>allow/disallow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/mail/sendmail.cf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) h)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6113-5' platform='hpux11.23' modified='2009-04-30'>
      <description>Sendmail should be configured with an appropriate logging level</description>
      <parameters>
        <parameter>logging level</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/mail/sendmail.cf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) i)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6047-5' platform='hpux11.23' modified='2009-04-30'>
      <description>Sendmail help command should be allowed or not as appropriate</description>
      <parameters>
        <parameter>allow/disallow</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via sendmail</technical_mechanism>
        <technical_mechanism>via /etc/mail/sendmail.cf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.2 (4) k)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6214-1' platform='hpux11.23' modified='2009-04-30'>
      <description>NIS+ server should operate at an appropriate security level</description>
      <parameters>
        <parameter>security level</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via NIS+</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.3 (1) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6051-7' platform='hpux11.23' modified='2009-04-30'>
      <description>X-Windows should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via Xwindows</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.4 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5756-2' platform='hpux11.23' modified='2009-04-30'>
      <description>Authorized X-clients should be listed or not in the X*.hosts file as appropriate</description>
      <parameters>
        <parameter>listed/not listed</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/X*.hosts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.4 (2) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5769-5' platform='hpux11.23' modified='2009-04-30'>
      <description>X-Windows should write .Xauthority files to users' home directories or not as appropriate</description>
      <parameters>
        <parameter>write/not write</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via xdm</technical_mechanism>
        <technical_mechanism>via gdm</technical_mechanism>
        <technical_mechanism>via kdm</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.4 (2) d)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5976-6' platform='hpux11.23' modified='2009-04-30'>
      <description>X11 forwarding via SSH should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via sshd_config</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.4 (2) f)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5438-7' platform='hpux11.23' modified='2009-04-30'>
      <description>Samba should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via smbd</technical_mechanism>
        <technical_mechanism>via RC scripts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.6 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6227-3' platform='hpux11.23' modified='2009-04-30'>
      <description>Samba 'hosts allow' option should be configured with an appropriate set of networks</description>
      <parameters>
        <parameter>list of networks</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via smbd</technical_mechanism>
        <technical_mechanism>via smb.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.6 (3) a)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5290-2' platform='hpux11.23' modified='2009-04-30'>
      <description>Samba 'security option' option should be set as appropriate</description>
      <parameters />
      <technical_mechanisms>
        <technical_mechanism>via smbd</technical_mechanism>
        <technical_mechanism>via smb.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.6 (3) b)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6192-9' platform='hpux11.23' modified='2009-04-30'>
      <description>Samba 'encrypt' passwords option should be set as appropriate</description>
      <parameters>
        <parameter>yes/no</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via smbd</technical_mechanism>
        <technical_mechanism>via smb.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.6 (3) c)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6165-5' platform='hpux11.23' modified='2009-04-30'>
      <description>Samba 'smb passwd file' option should be set to an appropriate password file or no password file</description>
      <parameters>
        <parameter>file/nothing</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via smbd</technical_mechanism>
        <technical_mechanism>via smb.conf</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.2.6 (3) d)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6262-0' platform='hpux11.23' modified='2009-04-30'>
      <description>IPv6 should be enabled or disabled as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via ifconfig</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.4.3 (1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6134-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/dev/kmem file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5315-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/dev/mem file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5912-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/dev/null file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6128-3' platform='hpux11.23' modified='2009-04-30'>
      <description>resolv.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5322-3' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/named.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #14</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6231-5' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/bin/at file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #25</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6082-2' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/bin/rdist file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #26</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6121-8' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/sbin/sync file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #27</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5452-8' platform='hpux11.23' modified='2009-04-30'>
      <description>Superuser account home directories' permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #29</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6280-2' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/samba/smb.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #31</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5332-2' platform='hpux11.23' modified='2009-04-30'>
      <description>smbpassword executable permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #32</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5782-8' platform='hpux11.23' modified='2009-04-30'>
      <description>Aliases file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #34</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5861-0' platform='hpux11.23' modified='2009-04-30'>
      <description>File permissions should be set as appropriate for the log file configured to capture critical sendmail messages.</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #35</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6248-9' platform='hpux11.23' modified='2009-04-30'>
      <description>All files executed through /etc/aliases file entries should have file permissions set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #36</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5592-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/bin/csh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #37</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5336-3' platform='hpux11.23' modified='2009-04-30'>
      <description>/bin/jsh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #38</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6205-9' platform='hpux11.23' modified='2009-04-30'>
      <description>/bin/ksh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #39</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6298-4' platform='hpux11.23' modified='2009-04-30'>
      <description>The /bin/rsh file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #40</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6331-3' platform='hpux11.23' modified='2009-04-30'>
      <description>/bin/sh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #41</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6300-8' platform='hpux11.23' modified='2009-04-30'>
      <description>/bin/bash file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #42</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5938-6' platform='hpux11.23' modified='2009-04-30'>
      <description>/sbin/csh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #43</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6027-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/sbin/jsh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #44</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5864-4' platform='hpux11.23' modified='2009-04-30'>
      <description>/sbin/ksh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #45</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5757-0' platform='hpux11.23' modified='2009-04-30'>
      <description>The /sbin/rsh file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #46</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6207-5' platform='hpux11.23' modified='2009-04-30'>
      <description>/sbin/sh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #47</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5973-3' platform='hpux11.23' modified='2009-04-30'>
      <description>/sbin/bash file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #48</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5341-3' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/bin/csh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #49</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6291-9' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/bin/jsh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #50</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6306-5' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/bin/ksh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #51</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5358-7' platform='hpux11.23' modified='2009-04-30'>
      <description>The /usr/bin/rsh file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #52</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6310-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/bin/sh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #53</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5904-8' platform='hpux11.23' modified='2009-04-30'>
      <description>snmpd.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #56</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6217-4' platform='hpux11.23' modified='2009-04-30'>
      <description>/tmp file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #57</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5494-0' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/tmp file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #58</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6221-6' platform='hpux11.23' modified='2009-04-30'>
      <description>.Xauthority file permissions should be set appropriately for all users.</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #60</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6314-9' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/aliases file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #61</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6327-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/cron.d/at.allow file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #62</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6032-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/cron.d/cron.allow file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #63</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5915-4' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/csh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #64</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5990-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/default/* file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #65</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6320-6' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/default/login file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #66</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6236-4' platform='hpux11.23' modified='2009-04-30'>
      <description>The /etc/ftpusers file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #69</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5950-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/host.lpd file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #70</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5362-9' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/hostname* file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #71</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6068-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/hosts file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #72</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6271-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/inetd.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #73</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6301-6' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/issue file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #75</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6275-2' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/jsh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #76</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6319-8' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/ksh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #77</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5649-9' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/mail/aliases file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #78</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5870-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/motd file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #79</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6274-5' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/netconfig file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #80</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5372-8' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/notrouter file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #81</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5439-5' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/pam.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #82</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5601-0' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/passwd file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #83</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6302-4' platform='hpux11.23' modified='2009-04-30'>
      <description>The /etc/rsh file should exist or not as appropriate</description>
      <parameters>
        <parameter>exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via filesystem</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #84</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5570-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/security file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #85</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6020-2' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/services file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #86</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5760-4' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/sh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #87</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5899-0' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/shadow file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #88</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6225-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/syslog.conf file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #89</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6242-2' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-6083-0' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/fstab file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #91</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5683-8' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5933-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/var/adm/loginlog file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #93</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6149-9' platform='hpux11.23' modified='2009-04-30'>
      <description>/var/adm/messages file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #94</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6039-2' platform='hpux11.23' modified='2009-04-30'>
      <description>/var/adm/sulog file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #95</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5655-6' platform='hpux11.23' modified='2009-04-30'>
      <description>/var/adm/utmp file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #96</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5854-5' platform='hpux11.23' modified='2009-04-30'>
      <description>/var/adm/wtmp file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #97</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6349-5' platform='hpux11.23' modified='2009-04-30'>
      <description>/var/adm/authlog file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #98</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6067-3' platform='hpux11.23' modified='2009-04-30'>
      <description>/var/adm/syslog file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #99</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5388-4' platform='hpux11.23' modified='2009-04-30'>
      <description>/var/mail file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #100</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5691-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/var/tmp file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #101</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5502-0' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/lib/pt_chmod file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #103</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5682-0' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/lib/embedded_us file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #104</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6259-6' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/lib/sendmail file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #105</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6210-9' platform='hpux11.23' modified='2009-04-30'>
      <description>/usr/kerberos/bin/rsh file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #107</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5871-9' platform='hpux11.23' modified='2009-04-30'>
      <description>/var/spool/mail file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #108</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5840-4' platform='hpux11.23' modified='2009-04-30'>
      <description>smbpassword file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 1) #109</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6353-7' platform='hpux11.23' modified='2009-04-30'>
      <description>System files should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #8</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5393-4' platform='hpux11.23' modified='2009-04-30'>
      <description>System files should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #8</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5399-1' platform='hpux11.23' modified='2009-04-30'>
      <description>Default/skeleton dot files should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6179-6' platform='hpux11.23' modified='2009-04-30'>
      <description>Default/skeleton dot files should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6272-9' platform='hpux11.23' modified='2009-04-30'>
      <description>Global initialization files should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5403-1' platform='hpux11.23' modified='2009-04-30'>
      <description>Global initialization files should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5746-3' platform='hpux11.23' modified='2009-04-30'>
      <description>Home directories should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5465-0' platform='hpux11.23' modified='2009-04-30'>
      <description>Home directories should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5729-9' platform='hpux11.23' modified='2009-04-30'>
      <description>inetd.conf file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5433-8' platform='hpux11.23' modified='2009-04-30'>
      <description>inetd.conf file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5879-2' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/services file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5447-8' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/services file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6046-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/notrouter file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #18</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5473-4' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/notrouter file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #18</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5404-9' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-6254-7' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5425-4' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/passwd file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #35</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6372-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/passwd file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #35</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6283-6' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/shadow file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #36</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6001-2' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/shadow file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.1 2) #36</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5451-0' platform='hpux11.23' modified='2009-04-30'>
      <description>Environmental variable PATH for superuser accounts should or should not contain world-writable files as appropriate</description>
      <parameters>
        <parameter>should/should not</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
        <technical_mechanism>via profile</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5467-6' platform='hpux11.23' modified='2009-04-30'>
      <description>Environmental variable PATH for superuser accounts should not contain the current directory as the first or last entry</description>
      <parameters>
        <parameter>should/should not</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via local init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6455-0' platform='hpux11.23' modified='2009-04-30'>
      <description>The current directory should or should not be added to the environmental variable PATH by global initialization files as appropriate</description>
      <parameters>
        <parameter>should/should not</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via local init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #3</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5486-6' platform='hpux11.23' modified='2009-04-30'>
      <description>The current directory should or should not be added to the environmental variable PATH by local initialization files as appropriate</description>
      <parameters>
        <parameter>should/should not</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via local init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6337-0' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-6289-3' platform='hpux11.23' modified='2009-04-30'>
      <description>The system umask should be set appropriately</description>
      <parameters>
        <parameter>umask</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via global init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #8</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6451-9' platform='hpux11.23' modified='2009-04-30'>
      <description>The user umask should be set appropriately</description>
      <parameters>
        <parameter>umask</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via local init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-1 A.2 1) #8</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6042-6' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5556-6' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/rc.config.d/auditing file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.1 1) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5887-5' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5962-6' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/init.d file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.1 1) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6365-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/hosts.lpd file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.1 1) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6211-7' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-5491-6' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/rc.config.d/auditing file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.1 1) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6313-1' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-6159-8' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/init.d file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.1 1) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6065-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/hosts.lpd file should be owned by an appropriate group</description>
      <parameters>
        <parameter>list of groups</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chgrp</technical_mechanism>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.1 1) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6251-3' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-6290-1' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/rc.config.d/auditing file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.1 1) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6360-2' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED in favor of CCE-8638-9, CCE-8647-0, and CCE-8187-7.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-8638-9' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/auto.master file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-3 C.1 1) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-8647-0' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/auto.misc file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-3 C.1 1) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-8187-7' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/auto.net file should be owned by an appropriate user</description>
      <parameters>
        <parameter>list of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-3 C.1 1) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5504-6' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/init.d file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.1 1) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5517-8' platform='hpux11.23' modified='2009-04-30'>
      <description>/etc/hosts.lpd file permissions should be set appropriately</description>
      <parameters>
        <parameter>permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via chmod</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.1 1) #6</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6076-4' platform='hpux11.23' modified='2009-04-30' deprecated='true'>
      <description>DEPRECATED.</description>
      <parameters />
      <technical_mechanisms />
      <references />
    </cce>
    <cce cce_id='CCE-6292-7' platform='hpux11.23' modified='2009-04-30'>
      <description>Auditing should be enabled or disabled for user accounts as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /tcb/files/auth/*</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 1)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6203-4' platform='hpux11.23' modified='2009-04-30'>
      <description>Auditing should be enabled or disabled at boot time as appropriate</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5794-3' platform='hpux11.23' modified='2009-04-30'>
      <description>System logons should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 3) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6168-9' platform='hpux11.23' modified='2009-04-30'>
      <description>System logoffs should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 3) #2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6014-5' platform='hpux11.23' modified='2009-04-30'>
      <description>Password changes should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 3) #3</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5983-2' platform='hpux11.23' modified='2009-04-30'>
      <description>su usage should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 3) #4</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5859-4' platform='hpux11.23' modified='2009-04-30'>
      <description>Creation/modification of superuser groups should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 3) #5</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6326-3' platform='hpux11.23' modified='2009-04-30'>
      <description>Clearing of the audit log file should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 3) #8</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5894-1' platform='hpux11.23' modified='2009-04-30'>
      <description>Startup/shutdown of audit functions should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 3) #9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6110-1' platform='hpux11.23' modified='2009-04-30'>
      <description>Use of identification/authorization mechanisms should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 3) #10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6423-8' platform='hpux11.23' modified='2009-04-30'>
      <description>Remote access from outside the corporate network should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 3) #11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6454-3' platform='hpux11.23' modified='2009-04-30'>
      <description>Change of permissions/privileges should be audited or not as appropriate</description>
      <parameters>
        <parameter>audited/not audited</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 3) #13</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6282-8' platform='hpux11.23' modified='2009-04-30'>
      <description>Global initialization files should allow or deny write access to the terminal as appropriate</description>
      <parameters>
        <parameter>allow/deny</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via global init files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.4 1) #1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6317-2' platform='hpux11.23' modified='2009-04-30'>
      <description>PRI audit file should be specified appropriately</description>
      <parameters>
        <parameter>file and path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5660-6' platform='hpux11.23' modified='2009-04-30'>
      <description>SEC audit file should be specified appropriately</description>
      <parameters>
        <parameter>file and path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6348-7' platform='hpux11.23' modified='2009-04-30'>
      <description>FileSpaceSwitch should be set to an appropriate value</description>
      <parameters>
        <parameter>percentage of free space</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5774-5' platform='hpux11.23' modified='2009-04-30'>
      <description>Wakeup switchpoint frequency should be set to an appropriate time interval</description>
      <parameters>
        <parameter>number of minutes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5731-5' platform='hpux11.23' modified='2009-04-30'>
      <description>Warning messages switchpoint distance should be set to an appropriate value</description>
      <parameters>
        <parameter>switchpoint distance integer</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/rc.config.d/auditing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10-4 D.3 2)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-6444-4' platform='hpux11.23' modified='2009-04-30'>
      <description>Hard core dump size limits should be set appropriately</description>
      <parameters>
        <parameter>Size (0 to disable core dumps)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>via /etc/security/limits</technical_mechanism>
        <technical_mechanism>via ulimit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.4.4 (3)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5940-2' platform='hpux11.23' modified='2009-04-30'>
      <description>Root logins should be allowed or not as appropriate from SSH consoles</description>
      <parameters>
        <parameter>allowed/not allowed</parameter>
      </parameters>
      <technical_mechanisms />
      <references>
        <reference resource_id='Internal Revenue Service Basic UNIX Security Requirements (IRS BUSR) http://www.irs.gov/irm/part10/ch03s08.html'>10.8.10.5.2.6 (4)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4017-0' platform='ie7' modified='2012-02-17'>
      <description>The "Security Zones: Use Only Machine Settings" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Use_HKLM_only </technical_mechanism>
        <technical_mechanism>Local Internet Options: </technical_mechanism>
        <technical_mechanism>GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism>Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-5</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1277, oval:org.mitre.oval:def:2050</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>UseOnlyMachineSettings-LocalComputer, UseOnlyMachineSettings-LocalComputer-Disabled</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>use_only_machine_settings_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1277</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3924-8' platform='ie7' modified='2012-02-17'>
      <description>Internet Explorer Processes (Restrict ActiveX Install)</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\(Reserved) </technical_mechanism>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\explorer.exe</technical_mechanism>
        <technical_mechanism> HKLM\Software\Policies\</technical_mechanism>
        <technical_mechanism>Local Internet Options: </technical_mechanism>
        <technical_mechanism>GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Restrict ActiveX Install</technical_mechanism>
        <technical_mechanism>Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\(Reserved)</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\explorer.exe</technical_mechanism>
        <technical_mechanism>[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL\iexplore.exe</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-119</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:658</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>IEProcesses-RestrictActiveXInstall-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>IEProcesses_RestrictActiveXInstall_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:658</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3929-7' platform='ie7' modified='2012-02-17'>
      <description>The "Security Zones: Do Not Allow Users to Add/Delete Sites" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_Zones_Map_Edit</technical_mechanism>
        <technical_mechanism>Local Internet Options: </technical_mechanism>
        <technical_mechanism>GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism>Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_zones_map_edit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-146</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1400</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DoNotAllowUsersAddDeleteSites-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DoNotAllowUsersAddDeleteSites_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1400</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3576-6' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Periodic Check For Internet Explorer Software Updates" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\InfoDelivery\Restrictions\NoUpdateCheck</technical_mechanism>
        <technical_mechanism>Local Internet Options: </technical_mechanism>
        <technical_mechanism>GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism>Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoUpdateCheck</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-212</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1357</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisablePeriodicCheckForIESoftwareUpdates-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DisablePeriodicCheckForIESoftwareUpdates_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1357</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4043-6' platform='ie7' modified='2012-02-17'>
      <description>Internet Explorer Processes (Zone Elevation Protection)</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\(Reserved)</technical_mechanism>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\explorer.exe</technical_mechanism>
        <technical_mechanism> HKLM\Software\Policies\Microsoft\Internet</technical_mechanism>
        <technical_mechanism>Local Internet Options: </technical_mechanism>
        <technical_mechanism>GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Protection From Zone Elevation</technical_mechanism>
        <technical_mechanism>Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\(Reserved)</technical_mechanism>
        <technical_mechanism>[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\explorer.exe</technical_mechanism>
        <technical_mechanism>[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION\iexplore.exe</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-347</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:620</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>IEProcesses_ProtectionFromZoneElevation_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:620</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4047-7' platform='ie7' modified='2012-02-17'>
      <description>The "Internet Explorer Processes (Consistent MIME Handling)" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\(Reserved)</technical_mechanism>
        <technical_mechanism> HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\explorer.exe</technical_mechanism>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet E</technical_mechanism>
        <technical_mechanism>Local Internet Options: </technical_mechanism>
        <technical_mechanism>GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Binary Behavior Security Restriction</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\(Reserved)</technical_mechanism>
        <technical_mechanism>[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\explorer.exe</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING\iexplore.exe</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-382</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:884</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>IEProcesses-ConsistentMimeHandling-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>IEProcesses_ConsistentMimeHandling_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:884</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3941-2' platform='ie7' modified='2012-02-17'>
      <description>The "Allow Software to Run or Install Even if the Signature is Invalid" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Download\RunInvalidSignatures</technical_mechanism>
        <technical_mechanism>Local Internet Options: </technical_mechanism>
        <technical_mechanism>GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Advanced Page </technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Download\RunInvalidSignatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-449</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:680, oval:org.mitre.oval:def:1392</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowSoftwareRunInstallSignatureInvalid-LocalComputer, AllowSoftwareToRununOrInstallEvenIfSignatureInvalid-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowSoftwareRunInstallSignatureInvalid_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:680</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3338-1' platform='ie7' modified='2012-02-17'>
      <description>The "Internet Explorer Processes (MK Protocol)" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\(Reserved)</technical_mechanism>
        <technical_mechanism> HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\explorer.exe</technical_mechanism>
        <technical_mechanism> HKLM\Software\Policies\Microsoft</technical_mechanism>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/MK Protocol Security Restriction</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\(Reserved)</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\explorer.exe</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\iexplore.exe</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-591</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:617</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>IEProcesses-MKProtocolSecurityRestriction-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>IEProcesses_MKProtocolSecurityRestriction_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:617</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4118-6' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Software Update Shell Notifications on Program Launch" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoMSAppLogo5ChannelNotify</technical_mechanism>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Restrict File Download</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\(Reserved)</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\explorer.exe</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\iexplore.exe</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-622</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1188</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableSoftwareUpdateShellNotifications-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DisableSoftwareUpdateShellNotifications_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1188</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4122-8' platform='ie7' modified='2012-02-17'>
      <description>The "Internet Explorer Processes (Restrict File Download)" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\(Reserved)</technical_mechanism>
        <technical_mechanism> HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\explorer.exe</technical_mechanism>
        <technical_mechanism> Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Restrict File Download</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\(Reserved)</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\explorer.exe</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD\iexplore.exe</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-668</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:320</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>IEProcesses-RestrictFileDownload-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>IEProcesses_RestrictFileDownload_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:320</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3518-8' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Automatic Install of Internet Explorer Components" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\InfoDelivery\Restrictions\NoJITSetup</technical_mechanism>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoJITSetup</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-684</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1198</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableAutomaticInstallOfIEComponents-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DisableAutomaticInstallOfIEComponents_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1198</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3201-1' platform='ie7' modified='2012-02-17'>
      <description>The "Make Proxy Settings Per-Machine (Rather Then Per-User)" setting should be configured correctly.</description>
      <parameters>
        <parameter>number of proxy settings</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ProxySettingsPerUser</technical_mechanism>
        <technical_mechanism>Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ProxySettingsPerUser</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-693</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1181</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>MakeProxySettingsPerMachine-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>MakeProxySettingsPerMachine_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1181</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3744-0' platform='ie7' modified='2012-02-17'>
      <description>The "Do Not Allow Users to enable or Disable Add-Ons" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoExtensionManagement</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-708</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1380, oval:org.mitre.oval:def:1358, oval:org.mitre.oval:def:1694</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DoNotAllowUsersEnableDisableAddOns-LocalComputer, DoNotAllowUsersEnableDisableAddOns-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DoNotAllowUsersEnableDisableAddOns_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1694</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3894-3' platform='ie7' modified='2012-02-17'>
      <description>The "Turn Off Crash Detection" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoCrashDetection</technical_mechanism>
        <technical_mechanism>Local Internet Options: GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoCrashDetection</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-753</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:487</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>TurnOffCrashDetection-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>TurnOffCrashDetection_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:487</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4162-4' platform='ie7' modified='2012-02-17'>
      <description>The "Internet Explorer Processes (Scripted Window Security Restrictions)" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\(Reserved)</technical_mechanism>
        <technical_mechanism> HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\explorer.exe</technical_mechanism>
        <technical_mechanism> Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Scripted Window Security Restrictions</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\(Reserved)</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\explorer.exe</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS\iexplore.exe</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-827</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:465</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>IEProcesses-ScriptedWindowSecurityRestrictions-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>IEProcesses_ScriptedWindowSecurityRestrictions_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:465</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3933-9' platform='ie7' modified='2012-02-17'>
      <description>The "Security Zones: Do Not Allow Users to Change Policies" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_options_edit</technical_mechanism>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_options_edit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-833</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1404</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DoNotAllowUsersChangePolicies-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DoNotAllowUsersChangePolicies_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1404</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4149-1' platform='ie7' modified='2012-02-17'>
      <description>The "Internet Explorer Processes (MIME Sniffing)" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\(Reserved)</technical_mechanism>
        <technical_mechanism> HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\explorer.exe</technical_mechanism>
        <technical_mechanism> Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Mime Sniffing Safety Feature</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\(Reserved)</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\explorer.exe</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING\iexplore.exe</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-985</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:317</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>IEProcesses-MimeSniffingSafetyFeature-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>IEProcesses_MimeSniffingSafetyFeature_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:317</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4026-1' platform='ie7' modified='2012-02-17'>
      <description>The "Check for Signature on Downloaded Programs" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Advanced Page </technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Download\CheckExeSignatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1025</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:395</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>CheckSignatureDownloadedPrograms-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>CheckSignatureDownloadedPrograms_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:395</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4171-5' platform='ie7' modified='2012-02-17'>
      <description>The "Do Not Allow Resetting Internet Explorer Settings" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Advanced Page </technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\DisableRIED</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-42</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:583</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DoNotAllowResettingIESettings-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DoNotAllowResettingIESettings_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:583</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4109-5' platform='ie7' modified='2012-02-17'>
      <description>The "Allow cut, copy, or paste operations from the clipboard via script" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1407</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-49</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:506, oval:org.mitre.oval:def:533</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowCutCopyPasteOperationsFromClipboardViaScript-InternetZone-LocalComputer, AllowCutCopyPasteOperationsFromClipboardViaScript-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>allow_cut_copy_paste_operations_from_clipboard_via_script_internet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:506</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3378-7' platform='ie7' modified='2012-02-17'>
      <description>The "Turn Off First- Run Opt-In" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1208</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-863</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1119</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>TurnOffFirst-RunOpt-In-InternetZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>TurnOffFirstRunOptIn_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1119</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4131-9' platform='ie7' modified='2012-02-17'>
      <description>The "Web Browser Applications" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2400</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-286</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:242</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>WebBrowserApplications-InternetZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>WebBrowserApplications_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:242</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4013-9' platform='ie7' modified='2012-02-17'>
      <description>The "Allow cut, copy, or paste operations from the clipboard via script" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1407</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1031</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:249, oval:org.mitre.oval:def:1393</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowCutCopyPasteOperationsFromClipboardViaScript-RestrictedSitesZone-LocalComputer, AllowCutCopyPasteOperationsFromClipboardViaScript-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowCutCopyPasteOperationsFromClipboardViaScript_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:249</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4153-3' platform='ie7' modified='2012-02-17'>
      <description>The "Turn Off First- Run Opt-In" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1208</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-200</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:621</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>TurnOffFirst-RunOpt-In-RestrictedSitesZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>TurnOffFirstRunOptIn_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:621</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4052-7' platform='ie7' modified='2012-02-17'>
      <description>The "Web Browser Applications" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2400</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-51</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:580</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>WebBrowserApplications-RestrictedSitesZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>WebBrowserApplications_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:580</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4175-6' platform='ie7' modified='2012-02-17'>
      <description>The "Intranet Sites: Include all network paths (UNCs)" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-876</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:559, oval:org.mitre.oval:def:1370</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>IncludeAllNetworkPaths-LocalComputer, IncludeAllNetworkPaths-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>include_all_network_paths_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:559</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3695-4' platform='ie7' modified='2012-02-17'>
      <description>The "Disable the Advanced Page" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\AdvancedTab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-810</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:934, oval:org.mitre.oval:def:660</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableTheAdvancedPage-LocalComputer, DisableTheAdvancedPage-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3777-0' platform='ie7' modified='2012-02-17'>
      <description>The "Disable the Privacy Page" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\PrivacyTab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-811</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1111</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableThePrivacyPage-LocalComputer</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3433-0' platform='ie7' modified='2012-02-17'>
      <description>The "Disable the Security Page" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\SecurityTab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-595</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:672, oval:org.mitre.oval:def:601</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableTheSecurityPage-LocalComputer, DisableTheSecurityPage-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4199-6' platform='ie7' modified='2012-02-17'>
      <description>The "Prevent Ignoing Certificate Errors" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\PreventIgnoreCertErrors</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-938</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:655, oval:org.mitre.oval:def:1129</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>PreventIgnoingCertificateErrors-LocalComputer, PreventIgnoingCertificateErrors-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>prevent_ignoring_certificate_errors_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:655</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3204-5' platform='ie7' modified='2012-02-17'>
      <description>The "Turn Off changing the URL to be displayed for checking updates to Internet Explorer and Internet Tools" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Internet Settings/Component Updates/Periodic Check for Updates to Internet Explorer and Internet Tools</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\Update_Check_Page</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-946</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:715</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>TurnOffChangingURLDisplay-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>TurnOffChangingURLDisplay_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:715</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4098-0' platform='ie7' modified='2012-02-17'>
      <description>The "Turn Off Configuring the Update Check Interval (In Days)" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Internet Settings/Component Updates/Periodic Check for Updates to Internet Explorer and Internet Tools</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\Update_Check_Interval</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-237</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1187</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>TurnOffConfiguringUpdateCheckInterval-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>TurnOffConfiguringUpdateCheckInterval_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1187</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3741-6' platform='ie7' modified='2012-02-17'>
      <description>The "Add-on List" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Add-on Management</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\ListBox_Support_CLSID</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-541</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:626</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AddOnList-LocalComputer</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3997-4' platform='ie7' modified='2012-02-17'>
      <description>The "Deny all add-ons unless specifically allowed in the Add-on List" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features/Add-on Management</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\RestrictToList</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-911</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1278</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DenyAllAddOns-LocalComputer</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4001-4' platform='ie7' modified='2012-02-17'>
      <description>The "Disable "Configuring History"" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\History</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-66</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:757, oval:org.mitre.oval:def:1365</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableConfiguringHistory-LocalComputer, DisableConfiguringHistory-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DisableConfiguringHistory_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:757</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4147-5' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Changing Automatic Configuration Settings" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\Autoconfig</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-471</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1285, oval:org.mitre.oval:def:613</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableChangingAutomaticConfigurationSettings-LocalComputer, DisableChangingAutomaticConfigurationSettings-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DisableChangingAutomaticConfigurationSettings_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1285</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4059-2' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Changing Connection Settings" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\Connection Settings</technical_mechanism>
        <technical_mechanism> [HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\Connwiz Admin Lock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-611</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:355, oval:org.mitre.oval:def:1128</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableChangingConnectionSettings-LocalComputer, DisableChangingConnectionSettings-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3935-4' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Changing Proxy Settings" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\Proxy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-62</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:398, oval:org.mitre.oval:def:635</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableChangingProxySettings-LocalComputer, DisableChangingProxySettings-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3706-9' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Showing the Splash Screen" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoSplash</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-556</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1164</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableShowingSplashScreen-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DisableShowingSplashScreen_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1164</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3975-0' platform='ie7' modified='2012-02-17'>
      <description>The "Prevent "Fix settings" Functionality" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Security\DisableFixSecuritySettings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-948</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:448, oval:org.mitre.oval:def:640</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>PreventFixSettingsFunctionality-LocalComputer, PreventFixSettingsFunctionality-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3993-3' platform='ie7' modified='2012-02-17'>
      <description>The "Prevent participation in the Customer Experience Improvement Programs" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\SQM\DisableCustomerImprovementProgram</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-495</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1171, oval:org.mitre.oval:def:1391</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>PreventParticipationInCustomerExperienceImprovementPrograms-LocalComputer, PreventParticipationInCustomerExperienceImprovementPrograms-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>PreventParticipationInCustomerExperienceImprovementPrograms_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1171</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3207-8' platform='ie7' modified='2012-02-17'>
      <description>The "Prevent performance of First Run Customize settings" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\DisableFirstRunCustomize</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1006</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1322</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>PreventPerformanceOfFirstRunCustomizeSettings-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>PreventPerformanceOfFirstRunCustomizeSettings_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1322</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4073-3' platform='ie7' modified='2012-02-17'>
      <description>The "Prevent the deletation of temporary internet files and cookies" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-909</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1382, oval:org.mitre.oval:def:703</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>PerventDeletationOfTempInternetFiles-LocalComputer, PerventDeletationOfTempInternetFiles-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3615-2' platform='ie7' modified='2012-02-17'>
      <description>The "Turn off "Delete Browsing History" functionality" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Control Panel\DisableDeleteBrowsingHistory</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1010</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:458, oval:org.mitre.oval:def:1474</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>TurnOffDeleteBrowsingHistoryFunctionality-LocalComputer, TurnOffDeleteBrowsingHistoryFunctionality-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>TurnOffDeleteBrowsingHistoryFunctionality_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:458</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3866-1' platform='ie7' modified='2012-02-17'>
      <description>The "Turn off Managing Phishing Filter" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\PhishingFilter\Enabled</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1032</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:501</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>TurnOffManagingPhishingFilter-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>TurnOffManagingPhishingFilter_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:501</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3875-2' platform='ie7' modified='2012-02-17'>
      <description>The "Turn off the Security Settings Check feature" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1054</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:916, oval:org.mitre.oval:def:1034</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>TurnOffSecuritySettingsCheckFeature-LocalComputer, TurnOffSecuritySettingsCheckFeature-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>TurnOffSecuritySettingsCheckFeature_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:916</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4174-9' platform='ie7' modified='2012-02-17'>
      <description>The "Allow Active Content from CD's to Run on User Machine" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Advanced Page </technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCAL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-964</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:400</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowActiveContentFromCD-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowActiveContentFromCD_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:400</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4192-1' platform='ie7' modified='2012-02-17'>
      <description>The "Enable third-party browser extensions" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Advanced Page </technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\Enable Browser Extensions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-598</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:110</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowThird-PartyBrowserExtensions-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowThird-PartyBrowserExtensions_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:110</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3584-0' platform='ie7' modified='2012-02-17'>
      <description>The "Automatically Check for Internet Explorer Updates" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Advanced Page </technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\NoUpdateCheck</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1008</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:656, oval:org.mitre.oval:def:1360</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AutomaticallyCheckIEUpdates-LocalComputer, AutomaticallyCheckForIEUpdates-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AutomaticallyCheckIEUpdates_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:656</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3976-8' platform='ie7' modified='2012-02-17'>
      <description>The "Check for Server Certificate Revocation" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Advanced Page </technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CertificateRevocation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-690</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:172, oval:org.mitre.oval:def:1502</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>CheckServerCertificateRevocation-LocalComputer, CheckForServerCertificateRevocation-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>CheckServerCertificateRevocation_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:172</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3853-9' platform='ie7' modified='2012-02-17'>
      <description>The "Access data sources across domains" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1406</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-47</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:674, oval:org.mitre.oval:def:650</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AccessDataSourcesAcrossDomains-InternetZone-LocalComputer, AccessDataSourcesAcrossDomains-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>access_data_sources_across_domains_internet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:674</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3998-2' platform='ie7' modified='2012-02-17'>
      <description>The "Drag and drop or copy and paste files" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1802</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-685</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1083, oval:org.mitre.oval:def:547</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowDragDropOrCopyPasteFiles-InternetZone-LocalComputer, AllowDragDropOrCopyPasteFiles-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowDragDropOrCopyPasteFiles_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1083</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3888-5' platform='ie7' modified='2012-02-17'>
      <description>The "Font download" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1604</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-491</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:524, oval:org.mitre.oval:def:659</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowFontDownloads-InternetZone-LocalComputer, AllowFontDownloads-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowFontDownloads_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:524</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3906-5' platform='ie7' modified='2012-02-17'>
      <description>The "Installation of desktop items" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1800</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-355</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:223, oval:org.mitre.oval:def:541</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowInstallationOfDesktopItems-InternetZone-LocalComputer, AllowInstallationOfDesktopItems-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowInstallationOfDesktopItems_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:223</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4099-8' platform='ie7' modified='2012-02-17'>
      <description>The "Allow script-initiated windows without size or position constraints" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2102</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-280</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:589, oval:org.mitre.oval:def:1476</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints-InternetZone-LocalComputer, AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:589</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3601-2' platform='ie7' modified='2012-02-17'>
      <description>The "Allow Scriptlets" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1209</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-439</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1043</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowScriptlets-InternetZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>allow_scriptlets_internet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1043</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3249-0' platform='ie7' modified='2012-02-17'>
      <description>The "Allow status bar updates via script" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2103</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-914</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:226, oval:org.mitre.oval:def:1208</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowStatusBarUpdatesViaScript-InternetZone-LocalComputer, AllowStatusBarUpdatesViaScript-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>allow_status_bar_updates_via_script_internet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:226</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4139-2' platform='ie7' modified='2012-02-17'>
      <description>The "Automatic prompting for file downloads" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2200</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-16</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1113, oval:org.mitre.oval:def:562</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AutomaticPromptingFileDownloads-InternetZone-LocalComputer, AutomaticPromptingFileDownloads-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AutomaticPromptingFileDownloads_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1113</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3927-1' platform='ie7' modified='2012-02-17'>
      <description>The "Download signed ActiveX controls" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1001</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1013</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1199, oval:org.mitre.oval:def:546</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DownloadSignedActiveXControls-InternetZone-LocalComputer, DownloadSignedActiveXControls-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>download_signed_activex_controls_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1199</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3945-3' platform='ie7' modified='2012-02-17'>
      <description>The "Download unsigned ActiveX controls" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1004</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-176</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:391, oval:org.mitre.oval:def:1200</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DownloadUnsignedActiveXControls-InternetZone-LocalComputer, DownloadUnsignedActiveXControls-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DownloadUnsignedActiveXControls_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:391</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4068-3' platform='ie7' modified='2012-02-17'>
      <description>The "Initialize and script ActiveX controls not marked as safe for scripting" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1201</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-586</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1040, oval:org.mitre.oval:def:739</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>InitializeScriptActiveXControlsNotMarkedAsSafe-InternetZone-LocalComputer, JavaPermissions-InternetZone-LocalComputer, InitializeScriptActiveXControlsNotMarkedAsSafe-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>InitializeScriptActiveXControlsNotMarkedAsSafe_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1040</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3963-6' platform='ie7' modified='2012-02-17'>
      <description>The "Java permissions" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>Custom/Disable Java/High safety/Low safety/Medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1C00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-132</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1174, oval:org.mitre.oval:def:725</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>JavaPermissions-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>java_permissions_internet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1174</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4104-6' platform='ie7' modified='2012-02-17'>
      <description>The "Launching programs and files in an IFRAME" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1804</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-689</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:611, oval:org.mitre.oval:def:1487</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>LaunchingApplicationsAndFilesInIFRAME-InternetZone-LocalComputer, LaunchingApplicationsAndFilesInIFRAME-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>LaunchingApplicationsAndFilesInIFRAME_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:611</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3623-6' platform='ie7' modified='2012-02-17'>
      <description>The "Logon" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>Anonymous logon/Automatic logon only in Intranet zone/Automatic logon with current user name and password/Prompt for user name and password</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1A00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-720</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:691, oval:org.mitre.oval:def:1123</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>LogonOptions-InternetZone-LocalComputer, LogonOptions-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>LogonOptions_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:691</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3751-5' platform='ie7' modified='2012-02-17'>
      <description>The "Loose XAML" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2402</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-126</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:240</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>LooseXAMLFiles-InternetZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>LooseXAMLFiles_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:240</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4143-4' platform='ie7' modified='2012-02-17'>
      <description>The "Navigate sub-frames across different domains" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1607</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-245</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:612, oval:org.mitre.oval:def:1394</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>NavigateSub-framesAcrossDifferentDomains-InternetZone-LocalComputer, NavigateSub-framesAcrossDifferentDomains-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>navigate_sub_frames_across_different_domains_Internet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:612</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4161-6' platform='ie7' modified='2012-02-17'>
      <description>The "Open files based on content, not file extension" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2100</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-910</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:953, oval:org.mitre.oval:def:1300</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>OpenFilesBasedOnContent-InternetZone-LocalComputer, OpenFilesBasedOnContent-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>OpenFilesBasedOnContent_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:953</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3553-5' platform='ie7' modified='2012-02-17'>
      <description>The "Software channel permissions" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>High safety/low safety/medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1E05</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-359</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:302, oval:org.mitre.oval:def:1398</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>SoftwareChannelPermissions-InternetZone-LocalComputer, SoftwareChannelPermissions-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>SoftwareChannelPermissions_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:302</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3619-4' platform='ie7' modified='2012-02-17'>
      <description>The "Use Pop-up Blocker" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1809</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1002</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1179, oval:org.mitre.oval:def:558</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>UsePop-upBlocker-InternetZone-LocalComputer, UsePop-upBlocker-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>UsePop-upBlocker_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1179</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3914-9' platform='ie7' modified='2012-02-17'>
      <description>The "Userdata persistence" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1606</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-425</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1108</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>UserdataPersistence-InternetZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>UserdataPersistence_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1108</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3570-9' platform='ie7' modified='2012-02-17'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2101</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-724</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:265, oval:org.mitre.oval:def:1432</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone-InternetZone-LocalComputer, WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone-InternetZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:265</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3843-0' platform='ie7' modified='2012-02-17'>
      <description>The "XPS documents" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2401</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1015</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:628</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>XPSFiles-InternetZone-LocalComputer</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3984-2' platform='ie7' modified='2012-02-17'>
      <description>The "Display mixed content" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Internet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1609</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-878</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:245</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisplayMixedContent-LockedDownInternetZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>display_mixed_content_locked_down_internet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:245</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3989-1' platform='ie7' modified='2012-02-17'>
      <description>The "Display mixed content" setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\1609</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-288</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1166</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisplayMixedContent-IntranetZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>display_mixed_content_intranet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1166</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4121-0' platform='ie7' modified='2012-02-17'>
      <description>The "Display mixed content" setting should be configured correctly for the Locked Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Intranet Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1\1609</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-552</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:247</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisplayMixedContent-LockedDownIntranetZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>display_mixed_content-LockedDownintranet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:247</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4138-4' platform='ie7' modified='2012-02-17'>
      <description>The "Display mixed content" setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Local Machine Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1609</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-473</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:383</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisplayMixedContent-LocalMachineZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>display_mixed_content-local_machine_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:383</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4028-7' platform='ie7' modified='2012-02-17'>
      <description>The "Display mixed content" setting should be configured correctly for the Locked Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Local Machine Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0\1609</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-239</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:418</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisplayMixedContent-LockedDownLocalMachineZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>display_mixed_content-LockedDownlocal_machine_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:418</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3905-7' platform='ie7' modified='2012-02-17'>
      <description>The "Access data sources across domains" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1406</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-636</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:652, oval:org.mitre.oval:def:750</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AccessDataSourcesAcrossDomains-RestrictedSitesZone-LocalComputer, AccessDataSourcesAcrossDomains-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AccessDataSourcesAcrossDomains_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:652</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4050-1' platform='ie7' modified='2012-02-17'>
      <description>The "Active scripting" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1400</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-292</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:293, oval:org.mitre.oval:def:561</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowActiveScripting-RestrictedSitesZone-LocalComputer, AllowActiveScripting-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowActiveScripting_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:293</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4196-2' platform='ie7' modified='2012-02-17'>
      <description>The "Binary and script behaviors" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>Administrator approved/enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2000</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-178</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:365, oval:org.mitre.oval:def:1314</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowBinaryAndScriptBehaviors-RestrictedSitesZone-LocalComputer, AllowBinaryAndScriptBehaviors-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowBinaryAndScriptBehaviors_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:365</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3337-3' platform='ie7' modified='2012-02-17'>
      <description>The "Drag and drop or copy and paste files" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1802</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-41</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:498, oval:org.mitre.oval:def:1465</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowDragDropOrCopyPasteFiles-RestrictedSitesZone-LocalComputer, AllowDragDropOrCopyPasteFiles-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowDragDropOrCopyPasteFiles_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:498</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4150-9' platform='ie7' modified='2012-02-17'>
      <description>The "File download" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1803</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-970</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1184, oval:org.mitre.oval:def:1318</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowFileDownloads-RestrictedSitesZone-LocalComputer, AllowFileDownloads-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowFileDownloads_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1184</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4062-6' platform='ie7' modified='2012-02-17'>
      <description>The "Font download" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1604</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-882</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1109, oval:org.mitre.oval:def:1410</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowFontDownloads-RestrictedSitesZone-LocalComputer, AllowFontDownloads-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowFontDownloads_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1109</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4079-0' platform='ie7' modified='2012-02-17'>
      <description>The "Installation of desktop items" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1800</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-763</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:251, oval:org.mitre.oval:def:1257</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowInstallationOfDesktopItems-RestrictedSitesZone-LocalComputer, AllowInstallationOfDesktopItems-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowInstallationOfDesktopItems_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:251</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4084-0' platform='ie7' modified='2012-02-17'>
      <description>The "Allow META REFRESH" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1608</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-680</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1218, oval:org.mitre.oval:def:1270</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowMETAREFRESH-RestrictedSitesZone-LocalComputer, AllowMETAREFRESH-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowMETAREFRESH_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1218</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4119-4' platform='ie7' modified='2012-02-17'>
      <description>The "Allow script-initiated windows without size or position constraints" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2102</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-208</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1234, oval:org.mitre.oval:def:574</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints-RestrictedSitesZone-LocalComputer, AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowScriptInitiatedWindowsWithoutSizeOrPositionConstraints_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1234</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3639-2' platform='ie7' modified='2012-02-17'>
      <description>The "Allow Scriptlets" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1209</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-838</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1217</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowScriptlets-RestrictedSitesZone-LocalComputer</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4031-1' platform='ie7' modified='2012-02-17'>
      <description>The "Allow status bar updates via script" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1001</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-129</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:378, oval:org.mitre.oval:def:1320</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowStatusBarUpdatesViaScript-RestrictedSitesZone-LocalComputer, AllowStatusBarUpdatesViaScript-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowStatusBarUpdatesViaScript_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:378</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4053-5' platform='ie7' modified='2012-02-17'>
      <description>The "Automatic prompting for file downloads" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2200</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-175</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:252, oval:org.mitre.oval:def:1312</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AutomaticPromptingFileDownloads-RestrictedSitesZone-LocalComputer, AutomaticPromptingFileDownloads-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AutomaticPromptingFileDownloads_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:252</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4057-6' platform='ie7' modified='2012-02-17'>
      <description>The "Download signed ActiveX controls" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1001</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-52</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1019, oval:org.mitre.oval:def:1389</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DownloadSignedActiveXControls-RestrictedSitesZone-LocalComputer, DownloadSignedActiveXControls-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>download_signed_activex_controls_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1019</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3564-2' platform='ie7' modified='2012-02-17'>
      <description>The "Download unsigned ActiveX controls" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1004</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1012</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:949, oval:org.mitre.oval:def:579</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DownloadUnsignedActiveXControls-RestrictedSitesZone-LocalComputer, DownloadUnsignedActiveXControls-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DownloadUnsignedActiveXControls_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:949</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4101-2' platform='ie7' modified='2012-02-17'>
      <description>The "Initialize and script ActiveX controls not marked as safe for scripting" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1201</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-26</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:273, oval:org.mitre.oval:def:1342</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>InitializeScriptActiveXControlsNotMarkedAsSafe-RestrictedSitesZone-LocalComputer, InitializeScriptActiveXControlsNotMarkedAsSafe-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>InitializeScriptActiveXControlsNotMarkedAsSafe_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:273</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3996-6' platform='ie7' modified='2012-02-17'>
      <description>The "Java permissions" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>Custom/Disable Java/High safety/Low safety/Medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1C00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-925</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:824, oval:org.mitre.oval:def:732</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>JavaPermissions-RestrictedSitesZone-LocalComputer, JavaPermissions-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>java_permissions_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:824</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4066-7' platform='ie7' modified='2012-02-17'>
      <description>The "Launching programs and files in an IFRAME" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1804</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-339</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:274, oval:org.mitre.oval:def:1223</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>LaunchingApplicationsAndFilesInIFRAME-RestrictedSitesZone-LocalComputer, LaunchingApplicationsAndFilesInIFRAME-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>LaunchingApplicationsAndFilesInIFRAME_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:274</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3696-2' platform='ie7' modified='2012-02-17'>
      <description>The "Logon" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>Anonymous logon/Automatic logon only in Intranet zone/Automatic logon with current user name and password/Prompt for user name and password</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1A00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-128</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:326, oval:org.mitre.oval:def:1378</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>LogonOptions-RestrictedSitesZone-LocalComputer, LogonOptions-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>LogonOptions_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:326</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3590-7' platform='ie7' modified='2012-02-17'>
      <description>The "Loose XAML" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2402</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-639</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:275</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>LooseXAMLFiles-RestrictedSitesZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>LooseXAMLFiles_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:275</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4110-3' platform='ie7' modified='2012-02-17'>
      <description>The "Navigate sub-frames across different domains" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1607</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-995</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1229, oval:org.mitre.oval:def:1292</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>NavigateSub-framesAcrossDifferentDomains-RestrictedSitesZone-LocalComputer, NavigateSub-framesAcrossDifferentDomains-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>NavigateSub-framesAcrossDifferentDomains_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1229</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4132-7' platform='ie7' modified='2012-02-17'>
      <description>The "Open files based on content, not file extension" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2100</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-409</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:706, oval:org.mitre.oval:def:1421</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>OpenFilesBasedOnContent-RestrictedSitesZone-LocalComputer, OpenFilesBasedOnContent-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>OpenFilesBasedOnContent_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:706</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3400-9' platform='ie7' modified='2012-02-17'>
      <description>The "Run components not signed with Authenticode" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2004</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-678</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:329, oval:org.mitre.oval:def:599</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>RunNETFrameworkReliantComponentsNotSignedWithAuthenticode-RestrictedSitesZone-LocalComputer, RunNETFrameworkReliantComponentsNotSignedWithAuthenticode-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>RunNETFrameworkReliantComponentsNotSignedWithAuthenticode_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:329</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4158-2' platform='ie7' modified='2012-02-17'>
      <description>The "Run components signed with Authenticode" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2001</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-563</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:276, oval:org.mitre.oval:def:1428</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>RunNETFrameworkReliantComponentsSignedWithAuthenticode-RestrictedSitesZone-LocalComputer, RunNETFrameworkReliantComponentsSignedWithAuthenticode-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>RunNETFrameworkReliantComponentsSignedWithAuthenticode_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:276</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4163-2' platform='ie7' modified='2012-02-17'>
      <description>The "Run ActiveX controls and plugins" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>Administrator approved/enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1200</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-841</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:571, oval:org.mitre.oval:def:1594</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>RunActiveXControlsAndPlugins-RestrictedSitesZone-LocalComputer, RunActiveXControlsAndPlugins-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>RunActiveXControlsAndPlugins_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:571</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4202-8' platform='ie7' modified='2012-02-17'>
      <description>The "Script ActiveX controls marked safe for scripting" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1405</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-973</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:602, oval:org.mitre.oval:def:1274</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>ScriptActiveXControlsMarkedSafeForScripting-RestrictedSitesZone-LocalComputer, ScriptActiveXControlsMarkedSafeForScripting-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>ScriptActiveXControlsMarkedSafeForScripting_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:602</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3216-9' platform='ie7' modified='2012-02-17'>
      <description>The "Scripting of Java applets" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1402</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1000</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:280, oval:org.mitre.oval:def:641</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>ScriptingOfJavaApplets-RestrictedSitesZone-LocalComputer, ScriptingOfJavaApplets-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>ScriptingOfJavaApplets_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:280</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3855-4' platform='ie7' modified='2012-02-17'>
      <description>The "Software channel permissions" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>High safety/low safety/medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1E05</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-520</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:290, oval:org.mitre.oval:def:1214</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>SoftwareChannelPermissions-RestrictedSitesZone-LocalComputer, SoftwareChannelPermissions-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>SoftwareChannelPermissions_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:290</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4018-8' platform='ie7' modified='2012-02-17'>
      <description>The "Use Pop-up Blocker" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1809</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-660</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1100, oval:org.mitre.oval:def:1286</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>UsePop-upBlocker-RestrictedSitesZone-LocalComputer, UsePop-upBlocker-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>UsePop-upBlocker_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1100</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4040-2' platform='ie7' modified='2012-02-17'>
      <description>The "Userdata persistence" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1606</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-28</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:300</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>UserdataPersistence-RestrictedSitesZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>UserdataPersistence_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:300</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4215-0' platform='ie7' modified='2012-02-17'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2101</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-698</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1219, oval:org.mitre.oval:def:1243</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone-RestrictedSitesZone-LocalComputer, WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone-RestrictedSitesZone-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>WebSitesInLessPrivilegedWebContentZonesCanNavigateIntoThisZone_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1219</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3991-7' platform='ie7' modified='2012-02-17'>
      <description>The "XPS documents" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2401</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-460</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1176</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>XPSFiles-RestrictedSitesZone-LocalComputer</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3264-9' platform='ie7' modified='2012-02-17'>
      <description>The "Display mixed content" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4\1609</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-30</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:314</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisplayMixedContent-LockedDownRestrictedSitesZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>display_mixed_content-LockedDownRestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:314</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4087-3' platform='ie7' modified='2012-02-17'>
      <description>The "Display mixed content" setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Trusted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\1609</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-31</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1153</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisplayMixedContent-TrustedSitesZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>display_mixed_content_trusted_sites_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1153</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4232-5' platform='ie7' modified='2012-02-17'>
      <description>The "Display mixed content" setting should be configured correctly for the Locked Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Trusted Sites Zone</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2\1609</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-666</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1183</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisplayMixedContent-LockedDownTrustedSitesZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>display_mixed_content_LockedDowntrusted_sites_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1183</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4259-8' platform='ie7' modified='2012-02-17'>
      <description>The "Enable Native XMLHttp Support" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Features</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Internet Explorer\Main\XMLHTTP</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-528</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:338</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>EnableNativeXMLHttpSupport-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>EnableNativeXMLHttpSupport_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:338</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3647-5' platform='ie7' modified='2012-02-17'>
      <description>The "Turn on the auto-complete feature for user names and passwords on form" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FormSuggest Passwords</technical_mechanism>
        <technical_mechanism> HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\FormSuggest Passwords</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-721</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:645</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableSaveThisProgramToDiskOption-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>TurnOnAutoCompleteFeatureForUserNamesAndPasswords_LocalUser</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:645</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3677-2' platform='ie7' modified='2012-02-17'>
      <description>The "Allow Install On Demand (Internet Explorer)" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKCU\Software\Policies\Microsoft\Internet Explorer\Main\NoJITSetup</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-69</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:523</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowInstallOnDemandIE-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>allow_install_on_demand_ie_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:9999</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4056-8' platform='ie7' modified='2012-02-17'>
      <description>The "Turn off page transitions" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKCU\Software\Policies\Microsoft\Internet Explorer\Main\Page_Transitions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-71</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1206</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>TurnOffPageTransitions-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>TurnOffPageTransitions_LocalUser</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1206</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4246-5' platform='ie7' modified='2012-02-17'>
      <description>The "Disable AutoComplete for forms" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKCU\Software\Policies\Microsoft\Internet Explorer\Main\Use FormSuggest</technical_mechanism>
        <technical_mechanism> HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\FormSuggest</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-478</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1516</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableAutoCompleteForForms-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DisableAutoCompleteForForms_LocalUser</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1516</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4214-3' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Save this program to disk option" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoSelectDownloadDir</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-412</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:505</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>AllowInstallOnDemandIE-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3606-1' platform='ie7' modified='2012-02-17'>
      <description>The "Disable changing certificate settings" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\Certificates</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1037</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1362</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableChangingCertificateSettings-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4237-4' platform='ie7' modified='2012-02-17'>
      <description>The "Disable external branding of Internet Explorer" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoExternalBranding</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1051</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1384</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableExternalBrandingOfIE-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DisableExternalBrandingOfIE_LocalUser</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1384</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3275-5' platform='ie7' modified='2012-02-17'>
      <description>The "Configure Outlook Express" setting should be configured correctly</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKCU\Software\Microsoft\Outlook Express\BlockExeAttachments</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-963</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1238</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>ConfigureOutlookExpress-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>configure_outlook_express_local_user</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1238</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4036-0' platform='ie7' modified='2012-02-17'>
      <description>The "Turn on the Internet Connection Wizard Auto Detect" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKCU\Software\Policies\Microsoft\Internet Connection Wizard\DisableICW</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-258</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:604</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>InternetConnectionWizardSettings-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>TurnOnInternetConnectionWizardAutoDetect_LocalUser</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:604</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3825-7' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Internet Connection wizard" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\Connwiz Admin Lock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-769</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1355</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableInternetConnectionWizard-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DisableInternetConnectionWizard_LocalUser</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1355</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4226-7' platform='ie7' modified='2012-02-17'>
      <description>The "Disable the Reset Web Settings feature" should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel\ResetWebSettings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-625</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1437</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableResetWebSettingsFeature-LocalUser</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>DisableResetWebSettingsFeature_LocalUser</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1437</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4120-2' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Downloading Of Site Subscription Content" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoSubscriptionContent</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-74</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1080</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableDownloadingOfSiteSubscriptionContent-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4248-1' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Adding Schedules For Offline Pages" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoAddingSubscriptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-122</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1293</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableAddingSchedulesForOfflinePages-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3389-4' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Adding Channels" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoAddingChannels</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-716</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1383</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableAddingChannels-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3645-9' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Editing And Creating Of Schedule Groups" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoEditingScheduleGroups</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-610</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1397</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableEditingAndCreatingOfScheduleGroups-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3940-4' platform='ie7' modified='2012-02-17'>
      <description>The "Disable All Scheduled Offline Pages" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoScheduledUpdates</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-619</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1501</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableAllScheduledOfflinePages-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3821-6' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Editing Schedules For Offline Pages" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoEditingSubscriptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-373</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1565</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableEditingSchedulesForOfflinePages-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3742-4' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Channel User Interface Completely" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoChannelUI</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-298</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1782</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableChannelUserInterfaceCompletely-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4261-4' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Removing Channels" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoRemovingChannels</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1069</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1801</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableRemovingChannels-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4190-5' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Removing Schedules For Offline Pages" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoRemovingSubscriptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-615</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1954</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableRemovingSchedulesForOfflinePages-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4208-5' platform='ie7' modified='2012-02-17'>
      <description>The "Disable Offline Page Hit Logging" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKCU\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoChannelLogging</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1003</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:2026</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>DisableOfflinePageHitLogging-LocalUser</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3754-9' platform='ie7' modified='2012-02-17'>
      <description>The "Java permissions" setting should be configured correctly for the Locked Down Intranet Zone.</description>
      <parameters>
        <parameter>Custom/Disable Java/High safety/Low safety/Medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Intranet Zone/Java permissions</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1\1C00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-320</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:2039</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>JavaPermissions-LockedDownIntranetZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>java_permissions_LockedDownintranet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:2039</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3891-9' platform='ie7' modified='2012-02-17'>
      <description>The "Java permissions" setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>Custom/Disable Java/High safety/Low safety/Medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Local Machine Zone/Java permissions</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1C00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-138</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1422</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>JavaPermissions-LocalMachineZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>java_permissions_local_machine_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1422</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4160-8' platform='ie7' modified='2012-02-17'>
      <description>The "Java permissions" setting should be configured correctly for the Locked Down Local Machine Zone.</description>
      <parameters>
        <parameter>Custom/Disable Java/High safety/Low safety/Medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Local Machine Zone/Java permissions</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0\1C00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1045</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 OVAL(SCAP-IE7-OVAL-Beta-v3.xml)'>oval:org.mitre.oval:def:1986</reference>
        <reference resource_id='NIST SCAP Microsoft Internet Explorer Version 7.0 XCCDF (SCAP-IE7-XCCDF-Beta-v3.xml'>JavaPermissions-LockedDownLocalMachineZone-LocalComputer</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>java_permissions_LockedDownlocal_machine_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1986</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4763-9' platform='ie7' modified='2012-02-17'>
      <description>Computer-wide, rather than per-user, assignment of sites to zones for Internet Explorer should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>enabled, disabled, or not configured</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>GPO Setting: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Site to Zone Assignment List</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1005</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>site_to_zone_assignment_list_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:9998</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4643-3' platform='ie7' modified='2012-02-17'>
      <description>The "Turn on Protected Mode" setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>GPO Setting: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Turn on Protected Mode</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-281</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>TurnOnProtectedMode_InternetZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:111999</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4652-4' platform='ie7' modified='2012-02-17'>
      <description>The "Java permissions" setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>Custom/Disable Java/High safety/Low safety/Medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Intranet Zone/Java permissions</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\1C00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-218</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>java_permissions_intranet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1883</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4793-6' platform='ie7' modified='2012-02-17'>
      <description>The "Download signed ActiveX controls" setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Internet Zone\Download signed ActiveX controls</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-308</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>download_signed_activex_controls_locked_down_internet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:24599</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4692-0' platform='ie7' modified='2012-02-17'>
      <description>The "Java permissions" setting should be configured correctly for the Locked Down Internet Zone.</description>
      <parameters>
        <parameter>Custom/Disable Java/High safety/Low safety/Medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Internet Zone/Java permissions</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3\1C00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-781</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>java_permissions_locked_down_internet_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1419</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3902-4' platform='ie7' modified='2012-02-17'>
      <description>The "Java permissions" setting should be configured correctly for the Locked Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>Custom/Disable Java/High safety/Low safety/Medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Restricted Sites Zone/Java permissions</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4\1C00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1088</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>java_permissions_LockedDownRestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1753</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4546-8' platform='ie7' modified='2012-02-17'>
      <description>The "Allow status bar updates via script" setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>GPO Settings:[Computer Configuration | User Configuration]/Network/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Trusted Sites Zone\Allow status bar updates via script</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1147</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>AllowStatusBarUpdatesViaScript_LockedDowntrusted_sites_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:118399</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4564-1' platform='ie7' modified='2012-02-17'>
      <description>The "Java permissions" setting should be configured correctly for the Locked Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>Custom/Disable Java/High safety/Low safety/Medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Locked-Down Trusted Sites Zone/Java permissions</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2\1C00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-140</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>java_permissions_LockedDowntrusted_sites_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1699</reference>
      </references>
    </cce>
    <cce cce_id='CCE-3909-9' platform='ie7' modified='2012-02-17'>
      <description>The "Turn on Protected Mode" setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>GPO Setting: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Turn on Protected Mode </technical_mechanism>
        <technical_mechanism>Registry Keys:[HKLM|HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1211</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>TurnOnProtectedMode_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:62199</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4845-4' platform='ie7' modified='2012-02-17'>
      <description>The "Java permissions" setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>Custom/Disable Java/High safety/Low safety/Medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Local Internet Options:</technical_mechanism>
        <technical_mechanism> GPO Settings:[Computer Configuration | User Configuration]/Administrative Templates/Windows Components/Internet Explorer/Internet Control Panel/Security Page/Trusted Sites Zone/Java permissions</technical_mechanism>
        <technical_mechanism> Registry Keys:[HKLM | HKCU]\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\1C00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-675</reference>
        <reference resource_id='FDCC IE7 XCCDF (fdcc-accepted-content-20080110\fdcc-ie7-xccdf.xml)'>java_permissions_trusted_sites_zone_local_computer</reference>
        <reference resource_id='FDCC IE7 OVAL (fdcc-accepted-content-20080110\fdcc-ie7-oval.xml'>oval:gov.nist.fdcc.ie7:def:1379</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18394-7' platform='ie7' modified='2012-02-17'>
      <description>The 'Allow scripting of Internet Explorer web browser control' setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1206</technical_mechanism>
        <technical_mechanism></technical_mechanism>
        <technical_mechanism>(2) Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='USGCB XCCDF (USGCB-Windows-ie7-xccdf)'>AllowScriptingOfInternetExplorerWebBrowserControl_InternetZone_LocalComputer</reference>
        <reference resource_id='USGCB OVAL (USGCB-Windows-ie7-oval)'>oval:gov.nist.USGCB.ie7:def:31098</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18552-0' platform='ie7' modified='2012-02-17'>
      <description>The 'Include local directory path when uploading files to a server' setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\160A</technical_mechanism>
        <technical_mechanism></technical_mechanism>
        <technical_mechanism>(2) Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Include local directory path when uploading files to a server</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='USGCB XCCDF (USGCB-Windows-ie7-xccdf)'>IncludeLocalDirectoryPathWhenUploadingFilesToAServer_InternetZone_LocalComputer</reference>
        <reference resource_id='USGCB OVAL (USGCB-Windows-ie7-oval)'>oval:gov.nist.USGCB.ie7:def:31099</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18467-1' platform='ie7' modified='2012-02-17'>
      <description>The 'Launching programs and unsafe files' setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1806</technical_mechanism>
        <technical_mechanism></technical_mechanism>
        <technical_mechanism>(2) Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Launching programs and unsafe files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='USGCB XCCDF (USGCB-Windows-ie7-xccdf)'>LaunchingProgramsAndUnsafeFiles_InternetZone_LocalComputer</reference>
        <reference resource_id='USGCB OVAL (USGCB-Windows-ie7-oval)'>oval:gov.nist.USGCB.ie7:def:31100</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18731-0' platform='ie7' modified='2012-02-17'>
      <description>The 'Run .NET Framework-reliant components not signed with Authenticode' setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2004</technical_mechanism>
        <technical_mechanism></technical_mechanism>
        <technical_mechanism>(2) Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Run .NET Framework-reliant components not signed with Authenticode</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='USGCB XCCDF (USGCB-Windows-ie7-xccdf)'>RunNETFrameworkReliantComponentsNotSignedWithAuthenticode_InternetZone_LocalComputer</reference>
        <reference resource_id='USGCB OVAL (USGCB-Windows-ie7-oval)'>oval:gov.nist.USGCB.ie7:def:31035</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18230-3' platform='ie7' modified='2012-02-17'>
      <description>The 'Run .NET Framework-reliant components signed with Authenticode' setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2001</technical_mechanism>
        <technical_mechanism></technical_mechanism>
        <technical_mechanism>(2) Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Run .NET Framework-reliant components signed with Authenticode</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='USGCB XCCDF (USGCB-Windows-ie7-xccdf)'>RunNETFrameworkReliantComponentsSignedWithAuthenticode_InternetZone_LocalComputer</reference>
        <reference resource_id='USGCB OVAL (USGCB-Windows-ie7-oval)'>oval:gov.nist.USGCB.ie7:def:31036</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18912-6' platform='ie7' modified='2012-02-17'>
      <description>The 'Allow scripting of Internet Explorer web browser control' setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1206</technical_mechanism>
        <technical_mechanism></technical_mechanism>
        <technical_mechanism>(2) Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='USGCB XCCDF (USGCB-Windows-ie7-xccdf)'>AllowScriptingOfInternetExplorerWebBrowserControl_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='USGCB OVAL (USGCB-Windows-ie7-oval)'>oval:gov.nist.USGCB.ie7:def:31103</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18738-5' platform='ie7' modified='2012-02-17'>
      <description>The 'Include local directory path when uploading files to a server' setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\160A</technical_mechanism>
        <technical_mechanism></technical_mechanism>
        <technical_mechanism>(2) Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Include local directory path when uploading files to a server</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='USGCB XCCDF (USGCB-Windows-ie7-xccdf)'>IncludeLocalDirectoryPathWhenUploadingFilesToAServer_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='USGCB OVAL (USGCB-Windows-ie7-oval)'>oval:gov.nist.USGCB.ie7:def:31104</reference>
      </references>
    </cce>
    <cce cce_id='CCE-18137-0' platform='ie7' modified='2012-02-17'>
      <description>The 'Launching programs and unsafe files' setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1806</technical_mechanism>
        <technical_mechanism></technical_mechanism>
        <technical_mechanism>(2) Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Launching programs and unsafe files</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='USGCB XCCDF (USGCB-Windows-ie7-xccdf)'>LaunchingProgramsAndUnsafeFiles_RestrictedSitesZone_LocalComputer</reference>
        <reference resource_id='USGCB OVAL (USGCB-Windows-ie7-oval)'>oval:gov.nist.USGCB.ie7:def:31105</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10002-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow cut, copy or paste operations from the clipboard via script" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow cut, copy or paste operations from the clipboard via script </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1407</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-49</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #32: This policy setting allows you to manage whether scripts can perform a clipboard operation (for example, cut, copy, and paste) in the security zone.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10004-0' platform='ie8' modified='2010-09-25'>
      <description>The "Only allow approved domains to use ActiveX controls without prompt" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Only allow approved domains to use ActiveX controls without prompt </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4\120b</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #20: This policy setting controls whether or not the user is prompted to allow ActiveX controls to run on Web sites other than the Web site that installed the ActiveX control.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10033-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow drag and drop or copy and paste files" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow drag and drop or copy and paste files </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1802</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-685</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #33: This policy setting allows you to manage whether users can drag files or copy and paste files from a source within the zone.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10037-0' platform='ie8' modified='2010-09-25'>
      <description>The "Security Zones: Do not allow users to change policies" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Zones: Do not allow users to change policies </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_options_edit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-833</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #91: If you enable this policy setting, you disable the Custom Level button and Security level for this zone slider on the Security tab in the Internet Options dialog box.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10052-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow software to run or install even if the signature is invalid" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Allow software to run or install even if the signature is invalid </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Download\RunInvalidSignatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-449</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #83: Allow software to run or install even if the signature is invalid</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10065-1' platform='ie8' modified='2010-09-25'>
      <description>The "Use SmartScreen Filter" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Use SmartScreen Filter </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2\2301</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #22: This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10074-3' platform='ie8' modified='2010-09-25'>
      <description>The "Check for server certificate revocation" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Check for server certificate revocation </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CertificateRevocation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-690</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #24: This policy setting allows you to manage whether Internet Explorer will check revocation status of servers' certificates.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10083-4' platform='ie8' modified='2010-09-25'>
      <description>The "Scripting of Java applets" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Scripting of Java applets </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1402</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1000</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #77: This policy setting allows you to manage whether applets are exposed to scripts within the zone.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10094-1' platform='ie8' modified='2010-09-25'>
      <description>The "Use Pop-up Blocker" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Use Pop-up Blocker </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1809</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-660</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #79: This policy setting allows you to manage whether unwanted pop-up windows appear.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10096-6' platform='ie8' modified='2010-09-25'>
      <description>The "Security Zones: Use only machine settings" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Zones: Use only machine settings </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-5</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #92: This policy setting affects how security zone changes apply to different users.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10107-1' platform='ie8' modified='2010-09-25'>
      <description>The "Open files based on content, not file extension" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Open files based on content, not file extension </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2100</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-910</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #46: This policy setting allows you to manage MIME sniffing for file promotion from one type to another based on a MIME sniff. A MIME sniff is the recognition by Internet Explorer of the file type based on a bit signature.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10138-6' platform='ie8' modified='2010-09-25'>
      <description>The "Consistent Mime Handling: Internet Explorer Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Consistent Mime Handling\Internet Explorer Processes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-382</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #7: When set to Enabled, Internet Explorer examines each received file for a consistent MIME type. When set to Disabled or Not configured, Internet Explorer does not require consistent MIME data from each file.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10145-1' platform='ie8' modified='2010-09-25'>
      <description>The "Use SmartScreen Filter" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Use SmartScreen Filter </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4\2301</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #21: This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10163-4' platform='ie8' modified='2010-09-25'>
      <description>The "Use SmartScreen Filter" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Use SmartScreen Filter </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1\2301</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #18: This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10182-4' platform='ie8' modified='2010-09-25'>
      <description>The "Java permissions" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>Custom/Disable Java/High safety/Low safety/Medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Java permissions </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1C00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-132</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #42: This policy setting allows you to manage permissions for Java applets.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10211-1' platform='ie8' modified='2010-09-25'>
      <description>The "Use SmartScreen Filter" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Use SmartScreen Filter </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\2301</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #15: This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10235-0' platform='ie8' modified='2010-09-25'>
      <description>The "Do not allow users to enable or disable add-ons" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Do not allow users to enable or disable add-ons </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoExtensionManagement</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-708</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #84: This policy setting allows you to manage whether users have the ability to allow or deny add-ons through Add-On Manager.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10253-3' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent "Fix settings" functionality" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\\Prevent "Fix settings" functionality </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Security\DisableFixSecuritySettings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-948</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #51: This policy setting prevents users from performing the "Fix settings" functionality related to the Security Settings Check in Internet Explorer.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10265-7' platform='ie8' modified='2010-09-25'>
      <description>The "MK Protocol Security Restriction: Internet Explorer Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\MK Protocol Security Restriction\Internet Explorer Processes </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL\(Reserved)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-591</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #9: When this setting is configured to Enabled, the MK protocol is blocked for Windows Explorer and Internet Explorer, which causes resources that use it to fail. When this setting is configured to Disabled, other applications can use the MK protocol API.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10277-2' platform='ie8' modified='2010-09-25'>
      <description>The "Open files based on content, not file extension" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Open files based on content, not file extension </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2100</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-409</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #72: This policy setting allows you to manage MIME sniffing for file promotion from one type to another based on a MIME sniff.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10291-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on the auto-complete feature for user names and passwords on forms" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn on the auto-complete feature for user names and passwords on forms </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FormSuggest Passwords</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-721</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #96: This policy setting controls automatic completion of user names and passwords in forms on Web pages, and prevents user prompts to save passwords.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10347-3' platform='ie8' modified='2010-09-25'>
      <description>The "Initialize and script ActiveX controls not marked as safe" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Initialize and script ActiveX controls not marked as safe </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1201</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-26</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #67: This policy setting allows you to manage ActiveX controls not marked as safe.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10360-6' platform='ie8' modified='2010-09-25'>
      <description>The "Launching applications and files in an IFRAME" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Launching applications and files in an IFRAME </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1804</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-339</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #69: This policy setting allows you to manage whether applications may be run and files may be downloaded from an IFRAME reference in the HTML of the pages in this zone.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10380-4' platform='ie8' modified='2010-09-25'>
      <description>The "Access data sources across domains" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Access data sources across domains </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1406</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-47</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #31: This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10387-9' platform='ie8' modified='2010-09-25'>
      <description>The "Disable "Configuring History"" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Delete Browsing History\Disable "Configuring History" </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Url History\DaysToKeep</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-66</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #25: This setting specifies the number of days that Internet Explorer keeps track of the pages viewed in the History List.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10388-7' platform='ie8' modified='2010-09-25'>
      <description>The "Disable AutoComplete for forms" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable AutoComplete for forms </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\FormSuggest</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-478</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #2: This policy setting controls automatic completion of fields in forms on Web pages.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10389-5' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for file downloads" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Automatic prompting for file downloads </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2200</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-16</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #38: This policy setting determines whether users will be prompted for non user-initiated file downloads.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10393-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active scripting" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow active scripting </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1400</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-292</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #54: This policy setting allows you to manage whether script code on pages in the zone is run</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10394-5' platform='ie8' modified='2010-09-25'>
      <description>The "Security Zones: Do not allow users to add/delete sites" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Zones: Do not allow users to add/delete sites </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_zones_map_edit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-146</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #90: Enable this policy setting to disable the site management settings for security zones.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10396-0' platform='ie8' modified='2010-09-25'>
      <description>The "Disable the Advanced page" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Disable the Advanced Page </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Control Panel\AdvancedTab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-810</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #29: This policy setting works in conjunction with other settings to ensure that users cannot change the settings that are configured in the Advanced tab of Internet Explorer.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10403-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow font downloads" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow font downloads </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1604</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-491</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #34: This policy setting allows you to manage whether pages of the zone may download HTML fonts.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10405-9' platform='ie8' modified='2010-09-25'>
      <description>The "Restrict ActiveX Install: Internet Explorer Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Restrict ActiveX Install\Internet Explorer Processes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-119</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #10: This policy setting provides the ability to block ActiveX control installation prompts for Internet Explorer processes.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10415-8' platform='ie8' modified='2010-09-25'>
      <description>The "Disable Save this program to disk option" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: User Configuration\Administrative Templates\Windows Components\Internet Explorer\Browser menus\Disable Save this program to disk option </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoSelectDownloadDir</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-412</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #5: This policy setting prevents users from saving a program or file that Internet Explorer has downloaded to the hard disk.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10431-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow status bar updates via script" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow status bar updates via script </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2103</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-129</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #63: This policy setting allows you to manage whether script is allowed to update the status bar within the zone.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10433-1' platform='ie8' modified='2010-09-25'>
      <description>The "Download unsigned ActiveX controls" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Download unsigned ActiveX controls </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1004</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-176</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #40: This policy setting allows you to manage whether users may download unsigned ActiveX controls from the zone.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10436-4' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent ignoring certificate errors" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Prevent ignoring certificate errors </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\PreventIgnoreCertErrors</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-938</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #52: When a user experiences Secure Socket Layer/Transport Layer Security (SSL/TLS) certificate errors such as "expired," "revoked," or "name mismatch," Internet Explorer blocks the user's ability to continue browsing the Web site.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10461-2' platform='ie8' modified='2010-09-25'>
      <description>The "Download unsigned ActiveX controls" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Download unsigned ActiveX controls </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1004</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1012</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #66: This policy setting allows you to manage whether users may download unsigned ActiveX controls from the zone.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10464-6' platform='ie8' modified='2010-09-25'>
      <description>The "Disable changing proxy settings" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable changing proxy settings </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Control Panel\Proxy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-62</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #28: This policy setting removes users' ability to change proxy settings.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10466-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow file downloads" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow file downloads </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1803</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-970</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #58: This policy setting allows you to manage whether file downloads are permitted from the zone.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10470-3' platform='ie8' modified='2010-09-25'>
      <description>The "Download signed ActiveX controls" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Download signed ActiveX controls </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1001</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-52</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #65: This policy setting allows you to manage whether users may download signed ActiveX controls from a page in the zone.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10472-9' platform='ie8' modified='2010-09-25'>
      <description>The "Logon options" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>Anonymous logon/Automatic logon only in Intranet zone/Automatic logon with current username and password/Prompt for user name and password</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Logon options </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1A00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-720</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #44: This policy setting allows you to manage settings for logon options.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10475-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow installation of desktop items" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow installation of desktop items </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1800</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-763</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #60: This policy setting allows you to manage whether users can install Active Desktop items from this zone.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10486-9' platform='ie8' modified='2010-09-25'>
      <description>The "Use Pop-up Blocker" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Use Pop-up Blocker </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1809</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1002</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #48: This policy setting allows you to manage whether unwanted pop-up windows appear. Pop-up windows that are opened when the end user clicks a link are not blocked.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10503-1' platform='ie8' modified='2010-09-25'>
      <description>The "Disable changing certificate settings" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable changing certificate settings </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel\Certificates</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1037</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #3: This policy setting removes a user's ability to change certificate settings in Internet Explorer.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10525-4' platform='ie8' modified='2010-09-25'>
      <description>The "Access data sources across domains" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Access data sources across domains </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1406</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-636</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #53: This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10539-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow cut, copy or paste operations from the clipboard via script" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow cut, copy or paste operations from the clipboard via script </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1407</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1031</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #56: This policy setting allows you to manage whether scripts can perform a clipboard operation (for example, cut, copy, and paste) in the security zone.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10547-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow binary and script behaviors" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/Administrator approved</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow binary and script behaviors </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2000</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-178</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #55: This policy setting allows you to manage dynamic binary and script behaviors.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10550-2' platform='ie8' modified='2010-09-25'>
      <description>The "Disable the Security page" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Disable the Security Page </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Control Panel\SecurityTab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-595</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #30: This policy setting removes the Security tab from the Internet Options dialog box.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10554-4' platform='ie8' modified='2010-09-25'>
      <description>The "Script ActiveX controls marked safe for scripting" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Script ActiveX controls marked safe for scripting </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1405</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-973</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #76: Restricted Sites Zone: Script ActiveX controls marked safe for scripting</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10561-9' platform='ie8' modified='2010-09-25'>
      <description>The "Initialize and script ActiveX controls not marked as safe" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Initialize and script ActiveX controls not marked as safe </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1201</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-586</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #41: This policy setting allows you to manage ActiveX controls not marked as safe.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10574-2' platform='ie8' modified='2010-09-25'>
      <description>The "Protection From Zone Elevation: Internet Explorer Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Protection From Zone Elevation\Internet Explorer Processes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-347</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #13: This setting controls the Internet Explorer restrictions on each Web page that it opens. These restrictions depend on the location of the Web page (such as Internet zone, Intranet zone, or Local Machine zone).</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10578-3' platform='ie8' modified='2010-09-25'>
      <description>The "Restrict File Download: Internet Explorer Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Restrict File Download\Internet Explorer Processes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-668</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #11: When set to Enabled, file download prompts that are not user-initiated are blocked for Internet Explorer processes. When set to Disabled, file download prompts will occur that are not user-initiated for Internet Explorer processes.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10581-7' platform='ie8' modified='2010-09-25'>
      <description>The "Automatically check for Internet Explorer updates" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Automatically check for Internet Explorer updates </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\NoUpdateCheck</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1008</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #23: This policy setting allows you to manage whether Internet Explorer checks the Internet for newer versions.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10594-0' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Crash Detection" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off Crash Detection </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\NoCrashDetection</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-753</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #94: This policy setting allows you to manage the crash detection feature of add-on management in Internet Explorer.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10604-7' platform='ie8' modified='2010-09-25'>
      <description>The "Scripted Window Security Restrictions: Internet Explorer Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Scripted Window Security Restrictions\Internet Explorer Processes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-827</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #12: When set to Enabled, pop-up windows will not display in Windows Explorer or for Internet Explorer processes. When set to Disabled or Do not configure, scripts can create pop-up windows and windows that can hide other windows.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10605-4' platform='ie8' modified='2010-09-25'>
      <description>The "Disable changing connection settings" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable changing connection settings </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Control Panel\Connection Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-611</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #27: This policy setting removes users' ability to change dial-up settings.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10607-0' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off the Security Settings Check feature" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off the Security Settings Check feature </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Security\DisableSecuritySettingsCheck</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1054</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #82: This policy setting turns off the Security Settings Check feature, which checks Internet Explorer security settings to determine when the settings put Internet Explorer at risk.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10609-6' platform='ie8' modified='2010-09-25'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Web sites in less privileged Web content zones can navigate into this zone </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2101</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-698</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #80: This policy setting allows you to manage whether Web sites from less privileged zones can navigate into this zone.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10620-3' platform='ie8' modified='2010-09-25'>
      <description>The "Java permissions" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>Custom/Disable Java/High safety/Low safety/Medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Java permissions </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1C00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1088</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #68: This policy setting allows you to manage permissions for Java applets.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10622-9' platform='ie8' modified='2010-09-25'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Web sites in less privileged Web content zones can navigate into this zone </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2101</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-724</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #49: This policy setting allows you to manage whether Web sites from less privileged zones can navigate into this zone.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10635-1' platform='ie8' modified='2010-09-25'>
      <description>The "Mime Sniffing Safety Feature: Internet Explorer Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Mime Sniffing Safety Feature\Internet Explorer Processes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-985</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #8: When set to Enabled, MIME sniffing will not promote a file of one type to a more dangerous file type. When set to Disabled, MIME sniffing configures Internet Explorer processes to allow the promotion of a file to a more dangerous file type.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10638-5' platform='ie8' modified='2010-09-25'>
      <description>The "Disable changing Automatic Configuration settings" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable changing Automatic Configuration settings </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Control Panel\Autoconfig</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-471</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #26: This policy setting removes a user's ability to change automatically configured settings.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10642-7' platform='ie8' modified='2010-09-25'>
      <description>The "Navigate windows and frames across different domains" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Navigate windows and frames across different domains </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1607</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-995</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #71: This policy setting allows you to manage the opening of sub-frames and access of applications across different domains.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10651-8' platform='ie8' modified='2010-09-25'>
      <description>The "Logon options" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>Anonymous logon/Automatic logon only in Intranet zone/Automatic logon with current username and password/Prompt for user name and password</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Logon options </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1A00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-128</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #70: This policy setting allows you to manage settings for logon options.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10664-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow META REFRESH" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow META REFRESH </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1608</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-680</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #61: This policy setting allows you to manage whether a user's browser can be redirected to another Web page if the author of the Web page uses the Meta Refresh setting to redirect browsers to another Web page.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9230-4' platform='ie8' modified='2010-09-25'>
      <description>The "Only use the ActiveX Installer Service for installation of ActiveX Controls" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Only use the ActiveX Installer Service for installation of ActiveX Controls </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\AxInstaller\OnlyUseAXISForActiveXInstall</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #85: This policy setting allows you to specify how ActiveX controls are installed.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9233-8' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent Bypassing SmartScreen Filter Warnings" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Prevent Bypassing SmartScreen Filter Warnings </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\PhishingFilter\PreventOverride</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #86: The SmartScreen Filter prevents users from navigating to and downloading from sites known to host malicious content, including Phishing or malicious software attacks.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9238-7' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent Deleting Cookies" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Delete Browsing History\Prevent Deleting Cookies </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Privacy\CleanCookies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #87: This policy setting is used to prevent users from deleting cookies.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9489-6' platform='ie8' modified='2010-09-25'>
      <description>The "Use SmartScreen Filter" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Use SmartScreen Filter </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3\2301</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #17: This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9504-2' platform='ie8' modified='2010-09-25'>
      <description>The "Disable Per-User Installation of ActiveX Controls" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable Per-User Installation of ActiveX Controls </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Security\ActiveX\BlockNonAdminActiveXInstall</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #4: This policy setting allows you to disable the per-user installation of ActiveX controls.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9580-2' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off ActiveX opt-in prompt" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off ActiveX opt-in prompt </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\NoFirsttimeprompt</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #93: This policy setting allows you to turn off the ActiveX opt-in prompt.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9599-2' platform='ie8' modified='2010-09-25'>
      <description>The "Only allow approved domains to use ActiveX controls without prompt" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Only allow approved domains to use ActiveX controls without prompt </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3\120b</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #16: This policy setting controls whether or not the user is prompted to allow ActiveX controls to run on Web sites other than the Web site that installed the ActiveX control.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9652-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Encryption Support" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Turn off Encryption Support </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\SecureProtocols</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #95: This policy setting allows you to turn off support for Transport Layer Security (TLS) 1.0, TLS 1.1, TLS 1.2, Secure Sockets Layer (SSL) 2.0 or SSL 3.0 in the browser.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9660-2' platform='ie8' modified='2010-09-25'>
      <description>The "Intranet Sites: Include all network paths (UNCs)" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Sites: Include all network paths (UNCs) </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\UNCAsIntranet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-876</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #50: This policy setting controls whether URLs representing UNCs are mapped into the local Intranet security zone.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9667-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow drag and drop or copy and paste files" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow drag and drop or copy and paste files </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1802</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-41</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #57: This policy setting allows you to manage whether users can drag files or copy and paste files from a source within the zone.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9669-3' platform='ie8' modified='2010-09-25'>
      <description>The "Software channel permissions" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>Low safety/Medium safety/High safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Software channel permissions </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1E05</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-520</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #78: This policy setting allows you to manage software channel permissions.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9673-5' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components signed with Authenticode" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Run .NET Framework-reliant components signed with Authenticode </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2001</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-563</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #74: This policy setting allows you to manage whether .NET Framework components that are signed with Authenticode can be executed from Internet Explorer.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9750-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow status bar updates via script" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow status bar updates via script </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2103</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-914</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #37: This policy setting allows you to manage whether script is allowed to update the status bar within the zone.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9775-8' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off "Delete Browsing History" functionality" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Delete Browsing History\Turn off  "Delete Browsing History" functionality </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Control Panel\DisableDeleteBrowsingHistory</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1010</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #81: This policy setting prevents users from performing the "Delete Browsing History" action in Internet Explorer.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9790-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow installation of desktop items" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow installation of desktop items </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1800</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-355</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #35: This policy setting allows you to manage whether users can install Active Desktop items from this zone.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9792-3' platform='ie8' modified='2010-09-25'>
      <description>The "Run ActiveX controls and plugins" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Run ActiveX controls and plugins </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1200</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-841</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #75: This policy setting allows you to manage whether ActiveX controls and plug-ins can be run on pages from the specified zone.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9793-1' platform='ie8' modified='2010-09-25'>
      <description>The "Only allow approved domains to use ActiveX controls without prompt" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Only allow approved domains to use ActiveX controls without prompt </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\120b</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #14: This policy setting controls whether or not the user is prompted to allow ActiveX controls to run on Web sites other than the Web site that installed the ActiveX control.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
        <reference resource_id='USGCB Beta 2010-08-31 XCCDF (USGCB-ie8_xccdf.xml)'>Rule 'OnlyAllowApprovedDomainsToUseActiveXControlsWithoutPrompt_InternetZone_LocalComputer'</reference>
        <reference resource_id='USGCB Beta 2010-08-31 OVAL (USGCB-ie8_oval.xml)'>Definition 'oval:gov.nist.USGCB.ie8:def:31101'</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9814-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow script-initiated windows without size or position constraints" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow script-initiated windows without size or position constraints </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2102</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-208</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #62: This policy setting allows you to manage restrictions on script-initiated pop-up windows and windows that include the title and status bars.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9821-0' platform='ie8' modified='2010-09-25'>
      <description>The "Launching applications and files in an IFRAME" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Launching applications and files in an IFRAME </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1804</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-689</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #43: This policy setting allows you to manage whether applications may be run and files may be downloaded from an IFRAME reference in the HTML of the pages in this zone.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9832-7' platform='ie8' modified='2010-09-25'>
      <description>The "Only allow approved domains to use ActiveX controls without prompt" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Only allow approved domains to use ActiveX controls without prompt </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\120b</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #89: This policy setting controls whether or not the user is prompted to allow ActiveX controls to run on Web sites other than the Web site that installed the ActiveX control.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
        <reference resource_id='USGCB Beta 2010-08-31 XCCDF (USGCB-ie8_xccdf.xml)'>Rule 'OnlyAllowApprovedDomainsToUseActiveXControlsWithoutPrompt_RestrictedSitesZone_LocalComputer'</reference>
        <reference resource_id='USGCB Beta 2010-08-31 OVAL (USGCB-ie8_oval.xml)'>Definition 'oval:gov.nist.USGCB.ie8:def:31106'</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9865-7' platform='ie8' modified='2010-09-25'>
      <description>The "Navigate windows and frames across different domains" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Navigate windows and frames across different domains </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1607</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-245</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #45: This policy setting allows you to manage the opening of sub-frames and access of applications across different domains.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9867-3' platform='ie8' modified='2010-09-25'>
      <description>The "Use SmartScreen Filter" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Use SmartScreen Filter </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0\2301</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #19: This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9869-9' platform='ie8' modified='2010-09-25'>
      <description>The 'Software channel permissions' setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>Low safety/Medium safety/High safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Software channel permissions </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1E05</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-359</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #47: This policy setting allows you to manage software channel permissions. If you enable this policy setting, you can choose the following options from the drop-down box:</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9882-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow script-initiated windows without size or position constraints" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow script-initiated windows without size or position constraints </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2102</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-280</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #36: This policy setting allows you to manage restrictions on script-initiated pop-up windows and windows that include the title and status bars.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9889-7' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent Deleting Temporary Internet Files" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Delete Browsing History\Prevent Deleting Temporary Internet Files </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Privacy\CleanTIF</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #88: This policy setting is used to prevent users from deleting temporary Internet files.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9898-8' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components not signed with Authenticode" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Run .NET Framework-reliant components not signed with Authenticode </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2004</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-678</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #73: Restricted Sites Zone: Run .NET Framework-reliant components not signed with Authenticode</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9917-6' platform='ie8' modified='2010-09-25'>
      <description>The "Download signed ActiveX controls" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Download signed ActiveX controls </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1001</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1013</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #39: This policy setting allows you to manage whether users may download signed ActiveX controls from a page in the zone.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9959-8' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for file downloads" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Automatic prompting for file downloads </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2200</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-175</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #64: This policy setting determines whether users will be prompted for non user-initiated file downloads.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9982-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow font downloads" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow font downloads </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1604</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-882</reference>
        <reference resource_id='Microsoft Security Compliance Management Toolkit for Internet Explorer 8, Version 1.0: "Internet Explorer 8 Security Baseline.xml"'>Setting Index #59: This policy setting allows you to manage whether pages of the zone may download HTML fonts.</reference>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10293-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active content from CDs to run on user machines" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Allow active content from CDs to run on user machines</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\Settings\LOCALMACHINE_CD_UNLOCK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9779-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow scripting of Internet Explorer web browser control" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
        <technical_mechanism>Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1206</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
        <reference resource_id='USGCB Beta 2010-08-31 XCCDF (USGCB-ie8_xccdf.xml)'>Rule 'AllowScriptingOfInternetExplorerWebBrowserControl_InternetZone_LocalComputer'</reference>
        <reference resource_id='USGCB Beta 2010-08-31 OVAL (USGCB-ie8_oval.xml)'>Definition 'oval:gov.nist.USGCB.ie8:def:31098'</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10725-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow scripting of Internet Explorer web browser control" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
        <technical_mechanism>Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1206</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
        <reference resource_id='USGCB Beta 2010-08-31 XCCDF (USGCB-ie8_xccdf.xml)'>Rule 'AllowScriptingOfInternetExplorerWebBrowserControl_RestrictedSitesZone_LocalComputer'</reference>
        <reference resource_id='USGCB Beta 2010-08-31 OVAL (USGCB-ie8_oval.xml)'>Definition 'oval:gov.nist.USGCB.ie8:def:31103'</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10685-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow Scriptlets" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow Scriptlets</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1209</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10630-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow Scriptlets" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow Scriptlets</technical_mechanism>
        <technical_mechanism>Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1209</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
        <reference resource_id='USGCB Beta 2010-08-31 XCCDF (USGCB-ie8_xccdf.xml)'>Rule 'AllowScriptlets_RestrictedSitesZone_LocalComputer'</reference>
        <reference resource_id='USGCB Beta 2010-08-31 OVAL (USGCB-ie8_oval.xml)'>Definition 'oval:gov.nist.USGCB.ie8:def:31061'</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10055-2' platform='ie8' modified='2010-09-25'>
      <description>The "Check for signatures on downloaded programs" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Check for signatures on downloaded programs</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Internet Explorer\Download]CheckExeSignatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10590-8' platform='ie8' modified='2010-09-25'>
      <description>The "Configure Delete Browsing History on exit" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Delete Browsing History\Configure Delete Browsing History on exit</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Internet Explorer\Privacy\ClearBrowsingHistoryOnExit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
        <reference resource_id='USGCB Beta 2010-08-31 XCCDF (USGCB-ie8_xccdf.xml)'>Rule 'ConfigureDeleteBrowsingHistoryonexit_LocalComputer'</reference>
        <reference resource_id='USGCB Beta 2010-08-31 OVAL (USGCB-ie8_oval.xml)'>Definition 'oval:gov.nist.USGCB.ie8:def:31095'</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9987-9' platform='ie8' modified='2010-09-25'>
      <description>The "Disable Automatic Install of Internet Explorer components" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable Automatic Install of Internet Explorer components</technical_mechanism>
        <technical_mechanism>Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoJITSetup</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-10634-4' platform='ie8' modified='2010-09-25'>
      <description>The "Disable Periodic Check For Internet Explorer Software Updates" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable Periodic Check for Internet Explorer software updates</technical_mechanism>
        <technical_mechanism>Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoUpdateCheck</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-10632-8' platform='ie8' modified='2010-09-25'>
      <description>The "Disable showing the splash screen" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable showing the splash screen</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions\NoSplash</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-10095-8' platform='ie8' modified='2010-09-25'>
      <description>The "Download signed ActiveX controls" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Download signed ActiveX controls</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3\1001</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9905-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow third-party browser extensions" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Allow third-party browser extensions</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Internet Explorer\Main\Enable Browser Extensions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10646-8' platform='ie8' modified='2010-09-25'>
      <description>The "Include local directory path when uploading files to a server" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Include local directory path when uploading files to a server</technical_mechanism>
        <technical_mechanism>Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\160A</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
        <reference resource_id='USGCB Beta 2010-08-31 XCCDF (USGCB-ie8_xccdf.xml)'>Rule 'IncludeLocalDirectoryPathWhenUploadingFilesToAServer_InternetZone_LocalComputer'</reference>
        <reference resource_id='USGCB Beta 2010-08-31 OVAL (USGCB-ie8_oval.xml)'>Definition 'oval:gov.nist.USGCB.ie8:def:31099'</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9781-6' platform='ie8' modified='2010-09-25'>
      <description>The "Include local directory path when uploading files to a server" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Include local directory path when uploading files to a server</technical_mechanism>
        <technical_mechanism>Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\160A</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
        <reference resource_id='USGCB Beta 2010-08-31 XCCDF (USGCB-ie8_xccdf.xml)'>Rule 'IncludeLocalDirectoryPathWhenUploadingFilesToAServer_RestrictedSitesZone_LocalComputer'</reference>
        <reference resource_id='USGCB Beta 2010-08-31 OVAL (USGCB-ie8_oval.xml)'>Definition 'oval:gov.nist.USGCB.ie8:def:31104'</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10603-9' platform='ie8' modified='2010-09-25'>
      <description>The "Include updated Web site lists from Microsoft" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Compatibility View\Include updated Web site lists from Microsoft</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation\MSCompatibilityMode</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
        <reference resource_id='USGCB Beta 2010-08-31 XCCDF (USGCB-ie8_xccdf.xml)'>Rule 'IncludeUpdatedWebsiteListsFromMicrosoft_LocalComputer'</reference>
        <reference resource_id='USGCB Beta 2010-08-31 OVAL (USGCB-ie8_oval.xml)'>Definition 'oval:gov.nist.USGCB.ie8:def:31094'</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10566-8' platform='ie8' modified='2010-09-25'>
      <description>The "Java permissions" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>Custom/Disable Java/High safety/Low safety/Medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Java permissions</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\1C00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10319-2' platform='ie8' modified='2010-09-25'>
      <description>The "Java permissions" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>Custom/Disable Java/High safety/Low safety/Medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Java permissions</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1C00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10597-3' platform='ie8' modified='2010-09-25'>
      <description>The "Java permissions" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>Custom/Disable Java/High safety/Low safety/Medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Java permissions</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3\1C00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10342-4' platform='ie8' modified='2010-09-25'>
      <description>The "Java permissions" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>Custom/Disable Java/High safety/Low safety/Medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Java permissions</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1\1C00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10535-3' platform='ie8' modified='2010-09-25'>
      <description>The "Java permissions" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>Custom/Disable Java/High safety/Low safety/Medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Java permissions</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0\1C00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10275-6' platform='ie8' modified='2010-09-25'>
      <description>The "Java permissions" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>Custom/Disable Java/High safety/Low safety/Medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Java permissions</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4\1C00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10654-2' platform='ie8' modified='2010-09-25'>
      <description>The "Java permissions" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>Custom/Disable Java/High safety/Low safety/Medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Java permissions</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2\1C00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10696-3' platform='ie8' modified='2010-09-25'>
      <description>The "Java permissions" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>Custom/Disable Java/High safety/Low safety/Medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Java permissions</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\1C00</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10650-0' platform='ie8' modified='2010-09-25'>
      <description>The "Launching programs and unsafe files" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Launching programs and unsafe files</technical_mechanism>
        <technical_mechanism>Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1806</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
        <reference resource_id='USGCB Beta 2010-08-31 XCCDF (USGCB-ie8_xccdf.xml)'>Rule 'LaunchingProgramsAndUnsafeFiles_InternetZone_LocalComputer'</reference>
        <reference resource_id='USGCB Beta 2010-08-31 OVAL (USGCB-ie8_oval.xml)'>Definition 'oval:gov.nist.USGCB.ie8:def:31100'</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10744-1' platform='ie8' modified='2010-09-25'>
      <description>The "Launching programs and unsafe files" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Launching programs and unsafe files</technical_mechanism>
        <technical_mechanism>Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1806</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
        <reference resource_id='USGCB Beta 2010-08-31 XCCDF (USGCB-ie8_xccdf.xml)'>Rule 'LaunchingProgramsAndUnsafeFiles_RestrictedSitesZone_LocalComputer'</reference>
        <reference resource_id='USGCB Beta 2010-08-31 OVAL (USGCB-ie8_oval.xml)'>Definition 'oval:gov.nist.USGCB.ie8:def:31105'</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10672-4' platform='ie8' modified='2010-09-25'>
      <description>The "Loose XAML files" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Loose XAML files</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2402</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10178-2' platform='ie8' modified='2010-09-25'>
      <description>The "Loose XAML files" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Loose XAML files</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2402</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9870-7' platform='ie8' modified='2010-09-25'>
      <description>The "Make proxy settings per-machine (rather than per-user)" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Make proxy settings per-machine (rather than per-user)</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ProxySettingsPerUser</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10110-5' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent Deleting Web sites that the User has Visited" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Delete Browsing History\Prevent Deleting Web sites that the User has Visited</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Internet Explorer\Privacy\CleanHistory</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
        <reference resource_id='USGCB Beta 2010-08-31 XCCDF (USGCB-ie8_xccdf.xml)'>Rule 'PreventDeletingWebsitesthattheUserhasVisited_LocalComputer'</reference>
        <reference resource_id='USGCB Beta 2010-08-31 OVAL (USGCB-ie8_oval.xml)'>Definition 'oval:gov.nist.USGCB.ie8:def:31096'</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10522-1' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent participation in the Customer Experience Improvement Program" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Prevent participation in the Customer Experience Improvement Program</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Internet Explorer\SQM\DisableCustomerImprovementProgram</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10641-9' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent performance of First Run Customize settings" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Prevent performance of First Run Customize settings</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Internet Explorer\Main\DisableFirstRunCustomize</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10515-5' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components signed with Authenticode" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Run .NET Framework-reliant components not signed with Authenticode</technical_mechanism>
        <technical_mechanism>Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2004</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
        <reference resource_id='USGCB Beta 2010-08-31 XCCDF (USGCB-ie8_xccdf.xml)'>Rule 'RunNETFrameworkReliantComponentsNotSignedWithAuthenticode_InternetZone_LocalComputer'</reference>
        <reference resource_id='USGCB Beta 2010-08-31 OVAL (USGCB-ie8_oval.xml)'>Definition 'oval:gov.nist.USGCB.ie8:def:31035'</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10625-2' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components not signed with Authenticode" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Run .NET Framework-reliant components signed with Authenticode</technical_mechanism>
        <technical_mechanism>Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2001</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
        <reference resource_id='USGCB Beta 2010-08-31 XCCDF (USGCB-ie8_xccdf.xml)'>Rule 'RunNETFrameworkReliantComponentsSignedWithAuthenticode_InternetZone_LocalComputer'</reference>
        <reference resource_id='USGCB Beta 2010-08-31 OVAL (USGCB-ie8_oval.xml)'>Definition 'oval:gov.nist.USGCB.ie8:def:31036'</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10425-7' platform='ie8' modified='2010-09-25'>
      <description>The "Software channel permissions" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>High safety/low safety/medium safety</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Software channel permissions</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1E05</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10595-7' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off changing the URL to be displayed for checking updates to Internet Explorer and Internet Tools" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Component Updates\Periodic check for updates to Internet Explorer and Internet Tools\Turn off changing the URL to be displayed for checking updates to Internet Explorer and Internet Tools</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Internet Explorer\Main\Update_Check_Page</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9776-6' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off configuring the update check interval (in days)" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Component Updates\Periodic check for updates to Internet Explorer and Internet Tools\Turn off configuring the update check interval (in days)</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Internet Explorer\Main\Update_Check_Interval</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14910-4' platform='ie8' modified='2010-09-25'>
      <description>The "Update Check Interval" should be set to the appropriate number of days.</description>
      <parameters>
        <parameter>number of days</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Component Updates\Periodic check for updates to Internet Explorer and Internet Tools\Turn off configuring the update check interval (in days) - Update check interval (in days)</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Internet Explorer\Main\Update_Check_Interval</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-10434-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn Off First-Run Opt-In" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Turn Off First-Run Opt-In</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1208</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10420-8' platform='ie8' modified='2010-09-25'>
      <description>The "Turn Off First-Run Opt-In" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Turn Off First-Run Opt-In</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4!1208</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9885-5' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off InPrivate Browsing" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\InPrivate\Turn off InPrivate Browsing</technical_mechanism>
        <technical_mechanism>Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Internet Explorer\Privacy\EnableInPrivateBrowsing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
        <reference resource_id='USGCB Beta 2010-08-31 XCCDF (USGCB-ie8_xccdf.xml)'>Rule 'TurnOffInPrivateBrowsing_LocalComputer'</reference>
        <reference resource_id='USGCB Beta 2010-08-31 OVAL (USGCB-ie8_oval.xml)'>Definition 'oval:gov.nist.USGCB.ie8:def:31097'</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10540-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Managing Phishing Filter" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off Managing Phishing filter</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Internet Explorer\PhishingFilter\Enabled</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-9973-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Managing SmartScreen Filter" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
        <parameter>(2) on/off</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off Managing SmartScreen Filter</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\Software\Policies\Microsoft\Internet Explorer\PhishingFilter\EnabledV8</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
        <reference resource_id='USGCB Beta 2010-08-31 XCCDF (USGCB-ie8_xccdf.xml)'>Rule 'TurnoffManagingSmartScreenFilter_LocalComputer'</reference>
        <reference resource_id='USGCB Beta 2010-08-31 OVAL (USGCB-ie8_oval.xml)'>Definition 'oval:gov.nist.USGCB.ie8:def:31093'</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10276-4' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Cross-Site Scripting (XSS) Filter" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Turn on Cross-Site Scripting (XSS) Filter</technical_mechanism>
        <technical_mechanism>Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1409</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
        <reference resource_id='USGCB Beta 2010-08-31 XCCDF (USGCB-ie8_xccdf.xml)'>Rule 'TurnonCrossSiteScriptingFilter_InternetZone_LocalComputer'</reference>
        <reference resource_id='USGCB Beta 2010-08-31 OVAL (USGCB-ie8_oval.xml)'>Definition 'oval:gov.nist.USGCB.ie8:def:31102'</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10105-5' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Cross-Site Scripting (XSS) Filter" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Turn on Cross-Site Scripting (XSS) Filter</technical_mechanism>
        <technical_mechanism>Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1409</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
        <reference resource_id='USGCB Beta 2010-08-31 XCCDF (USGCB-ie8_xccdf.xml)'>Rule 'TurnonCrossSiteScriptingFilter_RestrictedSitesZone_LocalComputer'</reference>
        <reference resource_id='USGCB Beta 2010-08-31 OVAL (USGCB-ie8_oval.xml)'>Definition 'oval:gov.nist.USGCB.ie8:def:31107'</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10676-5' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Protected Mode" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Turn on Protected Mode</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9945-7' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Protected Mode" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Turn on Protected Mode</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10200-4' platform='ie8' modified='2010-09-25'>
      <description>The "Userdata persistence" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Userdata persistence</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1606</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-9760-0' platform='ie8' modified='2010-09-25'>
      <description>The "Userdata persistence" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Userdata persistence</technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKLM\HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1606</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10829-0' platform='ie8' modified='2010-09-25'>
      <description>The "Disable external branding of Internet Explorer" current user setting should be configured correctly.</description>
      <parameters />
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable external branding of Internet Explorer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10701-1' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off page transitions" current user setting should be configured correctly.</description>
      <parameters />
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced settings\Browsing\Turn off page transitions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-10816-7' platform='ie8' modified='2010-09-25' deprecated='true'>
      <description>DEPRECATED.  Previously: The "Turn on the Internet Connection Wizard Auto Detect" setting should be configured correctly.  Note: According to Microsoft, does not apply to IE 8.</description>
      <parameters />
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced settings\Internet Connection Wizard Settings\Turn on the Internet Connection Wizard Auto Detect</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-10820-9' platform='ie8' modified='2010-09-25'>
      <description>The "Download signed ActiveX controls" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled/prompt</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO: Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Download signed ActiveX controls </technical_mechanism>
        <technical_mechanism>(2) Registry Key: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\1001</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16818-7' platform='ie8' modified='2010-09-25'>
      <description>The "Customize User Agent String" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Customize User Agent String</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17008-4' platform='ie8' modified='2010-09-25'>
      <description>The "Do not allow users to enable or disable add-ons" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Do not allow users to enable or disable add-ons</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17025-8' platform='ie8' modified='2010-09-25'>
      <description>The "Enforce Full Screen Mode" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Enforce Full Screen Mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16073-9' platform='ie8' modified='2010-09-25'>
      <description>The "Disable changing ratings settings" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable changing ratings settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16360-0' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Crash Detection" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off Crash Detection</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17043-1' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent Internet Explorer Search box from displaying" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Prevent Internet Explorer Search box from displaying</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16917-7' platform='ie8' modified='2010-09-25'>
      <description>The "Disable changing Temporary Internet files settings" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable changing Temporary Internet files settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17082-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off configuration of default behavior of new tab creation" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off configuration of default behavior of new tab creation</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\TabbedBrowsing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17007-6' platform='ie8' modified='2010-09-25'>
      <description>The "Disable Per-User Installation of ActiveX Controls" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable Per-User Installation of ActiveX Controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Security\ActiveX</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16902-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off tabbed browsing" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off tabbed browsing</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\TabbedBrowsing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16218-0' platform='ie8' modified='2010-09-25'>
      <description>The "Restrict changing the default search provider" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Restrict changing the default search provider</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17086-0' platform='ie8' modified='2010-09-25'>
      <description>The "Disable changing color settings" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable changing color settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16950-8' platform='ie8' modified='2010-09-25'>
      <description>The "Disable changing language settings" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable changing language settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17053-0' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent participation in the Customer Experience Improvement Program" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Prevent participation in the Customer Experience Improvement Program</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\SQM</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16511-8' platform='ie8' modified='2010-09-25'>
      <description>The "Only use the ActiveX Installer Service for installation of ActiveX Controls" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Only use the ActiveX Installer Service for installation of ActiveX Controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\AxInstaller</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16893-0' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off page zooming functionality" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off page zooming functionality</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\ZOOM</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16478-0' platform='ie8' modified='2010-09-25'>
      <description>The "Disable changing default browser check" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable changing default browser check</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16813-8' platform='ie8' modified='2010-09-25'>
      <description>The "Disable changing Messaging settings" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable changing Messaging settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16919-3' platform='ie8' modified='2010-09-25'>
      <description>The "Disable changing Advanced page settings" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable changing Advanced page settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16831-0' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off the activation of the quick pick menu" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off the activation of the quick pick menu</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\SearchScopes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16236-2' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Automatic Crash Recovery Prompt" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off Automatic Crash Recovery Prompt</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Recovery</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16906-0' platform='ie8' modified='2010-09-25'>
      <description>The "Disable changing Calendar and Contact settings" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable changing Calendar and Contact settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16752-8' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off displaying the Internet Explorer Help Menu" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off displaying the Internet Explorer Help Menu</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16474-9' platform='ie8' modified='2010-09-25'>
      <description>The "Disable changing proxy settings" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable changing proxy settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16113-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Quick Tabs functionality" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off Quick Tabs functionality</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\TabbedBrowsing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16626-4' platform='ie8' modified='2010-09-25'>
      <description>The "Disable caching of Auto-Proxy scripts" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable caching of Auto-Proxy scripts</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16090-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off ActiveX opt-in prompt" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off ActiveX opt-in prompt</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Ext</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16767-6' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off the auto-complete feature for web addresses" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off the auto-complete feature for web addresses</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Explorer\AutoComplete</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16756-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Reopen Last Browsing Session" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off Reopen Last Browsing Session</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Recovery</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16351-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off managing Pop-up filter level" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off managing Pop-up filter level</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16999-5' platform='ie8' modified='2010-09-25'>
      <description>The "Disable changing home page settings" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable changing home page settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17003-5' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on menu bar by default" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn on menu bar by default</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16356-8' platform='ie8' modified='2010-09-25'>
      <description>The "Disable changing link color settings" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable changing link color settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16285-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off configuration of window reuse" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off configuration of window reuse</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16977-1' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Tab Grouping" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off Tab Grouping</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\TabbedBrowsing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17020-9' platform='ie8' modified='2010-09-25'>
      <description>The "Set tab process growth" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Set tab process growth</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16267-7' platform='ie8' modified='2010-09-25'>
      <description>The "Disable Internet Connection wizard" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable Internet Connection wizard</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16364-2' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent performance of First Run Customize settings" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Prevent performance of First Run Customize settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16232-1' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Managing Pop-up Allow list" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off Managing Pop-up Allow list</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16093-7' platform='ie8' modified='2010-09-25'>
      <description>The "Configure new tab page default behavior" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Configure new tab page default behavior</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17018-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off pop-up management" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off pop-up management</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16088-7' platform='ie8' modified='2010-09-25'>
      <description>The "Disable changing secondary home page settings" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable changing secondary home page settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\SecondaryStartPages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16915-1' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent Bypassing SmartScreen Filter Warnings" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Prevent Bypassing SmartScreen Filter Warnings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\PhishingFilter</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16897-1' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent "Fix settings" functionality" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Prevent "Fix settings" functionality</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16699-1' platform='ie8' modified='2010-09-25'>
      <description>The "Restrict search providers to a specific list of providers" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Restrict search providers to a specific list of providers</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16263-6' platform='ie8' modified='2010-09-25'>
      <description>The "Disable changing Automatic Configuration settings" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable changing Automatic Configuration settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16079-6' platform='ie8' modified='2010-09-25'>
      <description>The "Disable changing accessibility settings" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable changing accessibility settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16620-7' platform='ie8' modified='2010-09-25'>
      <description>The "Pop-up allow list" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Pop-up allow list</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\New Windows</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16749-4' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off configuration of tabbed browsing pop-up behavior" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off configuration of tabbed browsing pop-up behavior</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\TabbedBrowsing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16406-1' platform='ie8' modified='2010-09-25'>
      <description>The "Display error message on proxy script download failure" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Display error message on proxy script download failure</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17035-7' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Managing SmartScreen Filter" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off Managing SmartScreen Filter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\PhishingFilter</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16663-7' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Suggested Sites" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn on Suggested Sites</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Suggested Sites</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17012-6' platform='ie8' modified='2010-09-25'>
      <description>The "Disable changing font settings" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable changing font settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16794-0' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Favorites bar" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off Favorites bar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\LinksBar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16994-6' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off suggestions for all user-installed providers" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off suggestions for all user-installed providers</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\SearchScopes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16227-1' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off the Security Settings Check feature" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off the Security Settings Check feature</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17031-6' platform='ie8' modified='2010-09-25'>
      <description>The "Use Automatic Detection for dial-up connections" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Use Automatic Detection for dial-up connections</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16295-8' platform='ie8' modified='2010-09-25'>
      <description>The "Disable changing connection settings" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable changing connection settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16091-1' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Compatibility Logging" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn on Compatibility Logging</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\Feature_Enable_Compat_logging</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17030-8' platform='ie8' modified='2010-09-25'>
      <description>The "Moving the menu bar above the navigation bar" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Moving the menu bar above the navigation bar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Toolbar\WebBrowser</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16487-1' platform='ie8' modified='2010-09-25'>
      <description>The "Add a specific list of search providers to the user's search provider list" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Add a specific list of search providers to the user's search provider list</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16840-1' platform='ie8' modified='2010-09-25'>
      <description>The "Disable Import/Export Settings wizard" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Disable Import/Export Settings wizard</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16033-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Accelerators" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Accelerators\Turn off Accelerators</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Activities</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16395-6' platform='ie8' modified='2010-09-25'>
      <description>The "Deploy default Accelerators" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Accelerators\Deploy default Accelerators</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\GPActivities\ActivitiesDefaultInstall</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16527-4' platform='ie8' modified='2010-09-25'>
      <description>The "Deploy non-default Accelerators" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Accelerators\Deploy non-default Accelerators</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\GPActivities\ActivitiesInstall</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16276-8' platform='ie8' modified='2010-09-25'>
      <description>The "Use Policy Accelerators" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Accelerators\Use Policy Accelerators</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Activities\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16852-6' platform='ie8' modified='2010-09-25'>
      <description>The "Deploy non-default Accelerators" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Accelerators\Deploy non-default Accelerators</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\GPActivities\ActivitiesInstall</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16874-0' platform='ie8' modified='2010-09-25'>
      <description>The "Deploy default Accelerators" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Accelerators\Deploy default Accelerators</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\GPActivities\ActivitiesDefaultInstall</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16848-4' platform='ie8' modified='2010-09-25'>
      <description>The "Use Policy Accelerators" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Accelerators\Use Policy Accelerators</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Activities\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16879-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Accelerators" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Accelerators\Turn off Accelerators</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Activities</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15702-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow scripting of Internet Explorer web browser control" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16370-9' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for ActiveX controls" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Automatic prompting for ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15641-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active content over restricted protocols to access my computer" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow active content over restricted protocols to access my computer</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16299-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to open windows without address or status bars" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow websites to open windows without address or status bars</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16363-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to prompt for information using scripted windows" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow websites to prompt for information using scripted windows</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15546-5' platform='ie8' modified='2010-09-25'>
      <description>The "Disable .NET Framework Setup" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Disable .NET Framework Setup</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16391-5' platform='ie8' modified='2010-09-25'>
      <description>The "Do not prompt for client certificate selection when no certificates or only one certificate exists." machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Do not prompt for client certificate selection when no certificates or only one certificate exists.</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16268-5' platform='ie8' modified='2010-09-25'>
      <description>The "XAML browser applications" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\XAML browser applications</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16537-3' platform='ie8' modified='2010-09-25'>
      <description>The "XPS documents" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\XPS documents</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16294-1' platform='ie8' modified='2010-09-25'>
      <description>The "Display mixed content" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Display mixed content</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15647-1' platform='ie8' modified='2010-09-25'>
      <description>The "Submit non-encrypted form data" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Submit non-encrypted form data</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15569-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow video and animation on a Web page that uses a legacy media player" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow video and animation on a Web page that uses a legacy media player</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15760-2' platform='ie8' modified='2010-09-25'>
      <description>The "Use SmartScreen Filter" machine setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Use SmartScreen Filter</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15727-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow the printing of background colors and images" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Advanced settings\Printing\Allow the printing of background colors and images</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16480-6' platform='ie8' modified='2010-09-25'>
      <description>The "Restrict ActiveX Install: Process List" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Restrict ActiveX Install\Process List</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16718-9' platform='ie8' modified='2010-09-25'>
      <description>The "Restrict ActiveX Install: All Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Restrict ActiveX Install\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15480-7' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent Deleting Favorites Site Data" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Delete Browsing History\Prevent Deleting Favorites Site Data</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Privacy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15022-7' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent Deleting Passwords" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Delete Browsing History\Prevent Deleting Passwords</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16001-0' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent Deleting InPrivate Filtering data" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Delete Browsing History\Prevent Deleting InPrivate Filtering data</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Privacy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15494-8' platform='ie8' modified='2010-09-25'>
      <description>The "Configure Delete Browsing History on exit" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Delete Browsing History\Configure Delete Browsing History on exit</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Privacy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15242-1' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent Deleting Form Data" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Delete Browsing History\Prevent Deleting Form Data</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16149-7' platform='ie8' modified='2010-09-25'>
      <description>The "Download unsigned ActiveX controls" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Download unsigned ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16173-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow binary and script behaviors" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow binary and script behaviors</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16197-6' platform='ie8' modified='2010-09-25'>
      <description>The "Submit non-encrypted form data" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Submit non-encrypted form data</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15201-7' platform='ie8' modified='2010-09-25'>
      <description>The "Download signed ActiveX controls" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Download signed ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16136-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow video and animation on a Web page that uses a legacy media player" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow video and animation on a Web page that uses a legacy media player</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15986-3' platform='ie8' modified='2010-09-25'>
      <description>The "Use Pop-up Blocker" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Use Pop-up Blocker</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15871-7' platform='ie8' modified='2010-09-25'>
      <description>The "Open files based on content, not file extension" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Open files based on content, not file extension</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15686-9' platform='ie8' modified='2010-09-25'>
      <description>The "Run ActiveX controls and plugins" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Run ActiveX controls and plugins</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16050-7' platform='ie8' modified='2010-09-25'>
      <description>The "Launching applications and files in an IFRAME" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Launching applications and files in an IFRAME</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15438-5' platform='ie8' modified='2010-09-25'>
      <description>The "Display mixed content" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Display mixed content</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15280-1' platform='ie8' modified='2010-09-25'>
      <description>The "Scripting of Java applets" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Scripting of Java applets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15220-7' platform='ie8' modified='2010-09-25'>
      <description>The "Access data sources across domains" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Access data sources across domains</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15825-3' platform='ie8' modified='2010-09-25'>
      <description>The "Initialize and script ActiveX controls not marked as safe" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Initialize and script ActiveX controls not marked as safe</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16078-8' platform='ie8' modified='2010-09-25'>
      <description>The "Turn Off First-Run Opt-In" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Turn Off First-Run Opt-In</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15515-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active content over restricted protocols to access my computer" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow active content over restricted protocols to access my computer</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16182-8' platform='ie8' modified='2010-09-25'>
      <description>The "Use SmartScreen Filter" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Use SmartScreen Filter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15968-1' platform='ie8' modified='2010-09-25'>
      <description>The "Disable .NET Framework Setup" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Disable .NET Framework Setup</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15305-6' platform='ie8' modified='2010-09-25'>
      <description>The "Include local directory path when uploading files to a server" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Include local directory path when uploading files to a server</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16169-5' platform='ie8' modified='2010-09-25'>
      <description>The "XPS documents" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\XPS documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15990-5' platform='ie8' modified='2010-09-25'>
      <description>The "Userdata persistence" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Userdata persistence</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15922-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow META REFRESH" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow META REFRESH</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15505-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow Scriptlets" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow Scriptlets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15347-8' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components signed with Authenticode" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Run .NET Framework-reliant components signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16083-8' platform='ie8' modified='2010-09-25'>
      <description>The "Logon options" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Logon options</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15652-1' platform='ie8' modified='2010-09-25'>
      <description>The "Only allow approved domains to use ActiveX controls without prompt" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Only allow approved domains to use ActiveX controls without prompt</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16028-3' platform='ie8' modified='2010-09-25'>
      <description>The "Navigate windows and frames across different domains" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Navigate windows and frames across different domains</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15809-7' platform='ie8' modified='2010-09-25'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Web sites in less privileged Web content zones can navigate into this zone</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15202-5' platform='ie8' modified='2010-09-25'>
      <description>The "Do not prompt for client certificate selection when no certificates or only one certificate exists." current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Do not prompt for client certificate selection when no certificates or only one certificate exists.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15667-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow script-initiated windows without size or position constraints" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow script-initiated windows without size or position constraints</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16201-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow cut, copy or paste operations from the clipboard via script" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow cut, copy or paste operations from the clipboard via script</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15783-4' platform='ie8' modified='2010-09-25'>
      <description>The "Launching programs and unsafe files" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Launching programs and unsafe files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15931-9' platform='ie8' modified='2010-09-25'>
      <description>The "XAML browser applications" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\XAML browser applications</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15675-2' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Cross-Site Scripting (XSS) Filter" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Turn on Cross-Site Scripting (XSS) Filter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15404-7' platform='ie8' modified='2010-09-25'>
      <description>The "Loose XAML files" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Loose XAML files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15730-5' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for file downloads" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Automatic prompting for file downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15356-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow installation of desktop items" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow installation of desktop items</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16017-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow font downloads" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow font downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16127-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow file downloads" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow file downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15211-6' platform='ie8' modified='2010-09-25'>
      <description>The "Java permissions" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Java permissions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16131-5' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for ActiveX controls" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Automatic prompting for ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15510-1' platform='ie8' modified='2010-09-25'>
      <description>The "Software channel permissions" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Software channel permissions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15223-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to prompt for information using scripted windows" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow websites to prompt for information using scripted windows</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15199-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active scripting" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow active scripting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15279-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Protected Mode" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Turn on Protected Mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15518-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow status bar updates via script" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow status bar updates via script</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16210-7' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components not signed with Authenticode" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Run .NET Framework-reliant components not signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15263-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to open windows without address or status bars" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow websites to open windows without address or status bars</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15254-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow drag and drop or copy and paste files" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow drag and drop or copy and paste files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15598-6' platform='ie8' modified='2010-09-25'>
      <description>The "Script ActiveX controls marked safe for scripting" current user setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Script ActiveX controls marked safe for scripting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15881-6' platform='ie8' modified='2010-09-25'>
      <description>The "Restrict File Download: All Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Restrict File Download\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16775-9' platform='ie8' modified='2010-09-25'>
      <description>The "Restrict File Download: Process List" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Restrict File Download\Process List</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15578-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow Scriptlets" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow Scriptlets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15649-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow script-initiated windows without size or position constraints" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow script-initiated windows without size or position constraints</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16338-6' platform='ie8' modified='2010-09-25'>
      <description>The "Include local directory path when uploading files to a server" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Include local directory path when uploading files to a server</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16602-5' platform='ie8' modified='2010-09-25'>
      <description>The "Disable .NET Framework Setup" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Disable .NET Framework Setup</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16408-7' platform='ie8' modified='2010-09-25'>
      <description>The "Software channel permissions" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Software channel permissions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15339-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow installation of desktop items" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow installation of desktop items</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15317-1' platform='ie8' modified='2010-09-25'>
      <description>The "Scripting of Java applets" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Scripting of Java applets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15532-5' platform='ie8' modified='2010-09-25'>
      <description>The "Java permissions" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Java permissions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15724-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow binary and script behaviors" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow binary and script behaviors</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15979-8' platform='ie8' modified='2010-09-25'>
      <description>The "Do not prompt for client certificate selection when no certificates or only one certificate exists." current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Do not prompt for client certificate selection when no certificates or only one certificate exists.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15838-6' platform='ie8' modified='2010-09-25'>
      <description>The "Display mixed content" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Display mixed content</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15712-3' platform='ie8' modified='2010-09-25'>
      <description>The "Userdata persistence" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Userdata persistence</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16168-7' platform='ie8' modified='2010-09-25'>
      <description>The "Include local directory path when uploading files to a server" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Include local directory path when uploading files to a server</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15734-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow font downloads" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow font downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17028-2' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components not signed with Authenticode" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Run .NET Framework-reliant components not signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15999-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow font downloads" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow font downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15690-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow video and animation on a Web page that uses a legacy media player" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow video and animation on a Web page that uses a legacy media player</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16063-0' platform='ie8' modified='2010-09-25'>
      <description>The "Download unsigned ActiveX controls" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Download unsigned ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16014-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Protected Mode" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Turn on Protected Mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15320-5' platform='ie8' modified='2010-09-25'>
      <description>The "Do not prompt for client certificate selection when no certificates or only one certificate exists." current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Do not prompt for client certificate selection when no certificates or only one certificate exists.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16187-7' platform='ie8' modified='2010-09-25'>
      <description>The "Launching programs and unsafe files" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Launching programs and unsafe files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16844-3' platform='ie8' modified='2010-09-25'>
      <description>The "Loose XAML files" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Loose XAML files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16441-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow installation of desktop items" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow installation of desktop items</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15622-4' platform='ie8' modified='2010-09-25'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Web sites in less privileged Web content zones can navigate into this zone</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15512-7' platform='ie8' modified='2010-09-25'>
      <description>The "Initialize and script ActiveX controls not marked as safe" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Initialize and script ActiveX controls not marked as safe</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16204-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow Scriptlets" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow Scriptlets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16983-9' platform='ie8' modified='2010-09-25'>
      <description>The "Use Pop-up Blocker" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Use Pop-up Blocker</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16177-8' platform='ie8' modified='2010-09-25'>
      <description>The "Navigate windows and frames across different domains" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Navigate windows and frames across different domains</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16174-5' platform='ie8' modified='2010-09-25'>
      <description>The "Only allow approved domains to use ActiveX controls without prompt" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Only allow approved domains to use ActiveX controls without prompt</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16015-0' platform='ie8' modified='2010-09-25'>
      <description>The "Initialize and script ActiveX controls not marked as safe" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Initialize and script ActiveX controls not marked as safe</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15102-7' platform='ie8' modified='2010-09-25'>
      <description>The "Use SmartScreen Filter" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Use SmartScreen Filter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16429-3' platform='ie8' modified='2010-09-25'>
      <description>The "Display mixed content" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Display mixed content</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16067-1' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for file downloads" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Automatic prompting for file downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15067-2' platform='ie8' modified='2010-09-25'>
      <description>The "Submit non-encrypted form data" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Submit non-encrypted form data</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16809-6' platform='ie8' modified='2010-09-25'>
      <description>The "Logon options" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Logon options</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16444-2' platform='ie8' modified='2010-09-25'>
      <description>The "Scripting of Java applets" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Scripting of Java applets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16505-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active scripting" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow active scripting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15963-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow binary and script behaviors" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow binary and script behaviors</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15976-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow drag and drop or copy and paste files" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow drag and drop or copy and paste files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16215-6' platform='ie8' modified='2010-09-25'>
      <description>The "Initialize and script ActiveX controls not marked as safe" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Initialize and script ActiveX controls not marked as safe</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16117-4' platform='ie8' modified='2010-09-25'>
      <description>The "Logon options" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Logon options</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15747-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to open windows without address or status bars" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow websites to open windows without address or status bars</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16430-1' platform='ie8' modified='2010-09-25'>
      <description>The "Open files based on content, not file extension" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Open files based on content, not file extension</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15327-0' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Cross-Site Scripting (XSS) Filter" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Turn on Cross-Site Scripting (XSS) Filter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16219-8' platform='ie8' modified='2010-09-25'>
      <description>The "Only allow approved domains to use ActiveX controls without prompt" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Only allow approved domains to use ActiveX controls without prompt</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16561-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow video and animation on a Web page that uses a legacy media player" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow video and animation on a Web page that uses a legacy media player</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15323-9' platform='ie8' modified='2010-09-25'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Web sites in less privileged Web content zones can navigate into this zone</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15882-4' platform='ie8' modified='2010-09-25'>
      <description>The "Disable .NET Framework Setup" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Disable .NET Framework Setup</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15636-4' platform='ie8' modified='2010-09-25'>
      <description>The "Download unsigned ActiveX controls" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Download unsigned ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15873-3' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components not signed with Authenticode" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Run .NET Framework-reliant components not signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15351-0' platform='ie8' modified='2010-09-25'>
      <description>The "Launching programs and unsafe files" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Launching programs and unsafe files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16642-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow Scriptlets" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow Scriptlets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16457-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow cut, copy or paste operations from the clipboard via script" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow cut, copy or paste operations from the clipboard via script</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16898-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow scripting of Internet Explorer web browser control" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15773-5' platform='ie8' modified='2010-09-25'>
      <description>The "Turn Off First-Run Opt-In" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Turn Off First-Run Opt-In</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15538-2' platform='ie8' modified='2010-09-25'>
      <description>The "Disable .NET Framework Setup" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Disable .NET Framework Setup</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16036-6' platform='ie8' modified='2010-09-25'>
      <description>The "Download signed ActiveX controls" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Download signed ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16522-5' platform='ie8' modified='2010-09-25'>
      <description>The "Do not prompt for client certificate selection when no certificates or only one certificate exists." current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Do not prompt for client certificate selection when no certificates or only one certificate exists.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16314-7' platform='ie8' modified='2010-09-25'>
      <description>The "Open files based on content, not file extension" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Open files based on content, not file extension</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16184-4' platform='ie8' modified='2010-09-25'>
      <description>The "Java permissions" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Java permissions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15500-2' platform='ie8' modified='2010-09-25'>
      <description>The "Access data sources across domains" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Access data sources across domains</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16129-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow binary and script behaviors" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow binary and script behaviors</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16407-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Protected Mode" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Turn on Protected Mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16270-1' platform='ie8' modified='2010-09-25'>
      <description>The "Submit non-encrypted form data" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Submit non-encrypted form data</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15692-7' platform='ie8' modified='2010-09-25'>
      <description>The "Java permissions" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Java permissions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15096-1' platform='ie8' modified='2010-09-25'>
      <description>The "Loose XAML files" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Loose XAML files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15091-2' platform='ie8' modified='2010-09-25'>
      <description>The "Only allow approved domains to use ActiveX controls without prompt" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Only allow approved domains to use ActiveX controls without prompt</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16335-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active scripting" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow active scripting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16562-1' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for file downloads" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Automatic prompting for file downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15105-0' platform='ie8' modified='2010-09-25'>
      <description>The "Download signed ActiveX controls" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Download signed ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15599-4' platform='ie8' modified='2010-09-25'>
      <description>The "Submit non-encrypted form data" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Submit non-encrypted form data</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15066-4' platform='ie8' modified='2010-09-25'>
      <description>The "Launching applications and files in an IFRAME" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Launching applications and files in an IFRAME</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15200-9' platform='ie8' modified='2010-09-25'>
      <description>The "XAML browser applications" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\XAML browser applications</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16459-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow script-initiated windows without size or position constraints" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow script-initiated windows without size or position constraints</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16181-0' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Cross-Site Scripting (XSS) Filter" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Turn on Cross-Site Scripting (XSS) Filter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15926-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to open windows without address or status bars" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow websites to open windows without address or status bars</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15601-8' platform='ie8' modified='2010-09-25'>
      <description>The "Logon options" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Logon options</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16040-8' platform='ie8' modified='2010-09-25'>
      <description>The "Launching programs and unsafe files" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Launching programs and unsafe files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15693-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow script-initiated windows without size or position constraints" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow script-initiated windows without size or position constraints</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16434-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow status bar updates via script" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow status bar updates via script</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16234-7' platform='ie8' modified='2010-09-25'>
      <description>The "Run ActiveX controls and plugins" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Run ActiveX controls and plugins</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16281-8' platform='ie8' modified='2010-09-25'>
      <description>The "Scripting of Java applets" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Scripting of Java applets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16479-8' platform='ie8' modified='2010-09-25'>
      <description>The "Download unsigned ActiveX controls" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Download unsigned ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16374-1' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Cross-Site Scripting (XSS) Filter" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Turn on Cross-Site Scripting (XSS) Filter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16226-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow script-initiated windows without size or position constraints" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow script-initiated windows without size or position constraints</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16206-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow Scriptlets" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow Scriptlets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16466-5' platform='ie8' modified='2010-09-25'>
      <description>The "XPS documents" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\XPS documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17227-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow font downloads" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow font downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16176-0' platform='ie8' modified='2010-09-25'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Web sites in less privileged Web content zones can navigate into this zone</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16361-8' platform='ie8' modified='2010-09-25'>
      <description>The "Open files based on content, not file extension" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Open files based on content, not file extension</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16816-1' platform='ie8' modified='2010-09-25'>
      <description>The "Disable .NET Framework Setup" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Disable .NET Framework Setup</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15876-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow META REFRESH" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow META REFRESH</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15832-9' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components signed with Authenticode" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Run .NET Framework-reliant components signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16296-6' platform='ie8' modified='2010-09-25'>
      <description>The "Software channel permissions" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Software channel permissions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16426-9' platform='ie8' modified='2010-09-25'>
      <description>The "Script ActiveX controls marked safe for scripting" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Script ActiveX controls marked safe for scripting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16449-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to open windows without address or status bars" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow websites to open windows without address or status bars</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15076-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to prompt for information using scripted windows" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow websites to prompt for information using scripted windows</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16220-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow file downloads" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow file downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15044-1' platform='ie8' modified='2010-09-25'>
      <description>The "Turn Off First-Run Opt-In" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Turn Off First-Run Opt-In</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16211-5' platform='ie8' modified='2010-09-25'>
      <description>The "Display mixed content" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Display mixed content</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15862-6' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components not signed with Authenticode" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Run .NET Framework-reliant components not signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16180-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow status bar updates via script" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow status bar updates via script</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16359-2' platform='ie8' modified='2010-09-25'>
      <description>The "XAML browser applications" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\XAML browser applications</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15558-0' platform='ie8' modified='2010-09-25'>
      <description>The "Script ActiveX controls marked safe for scripting" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Script ActiveX controls marked safe for scripting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16452-5' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for file downloads" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Automatic prompting for file downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15620-8' platform='ie8' modified='2010-09-25'>
      <description>The "Software channel permissions" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Software channel permissions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16381-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to prompt for information using scripted windows" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow websites to prompt for information using scripted windows</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16024-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow META REFRESH" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow META REFRESH</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17238-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to open windows without address or status bars" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow websites to open windows without address or status bars</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16492-1' platform='ie8' modified='2010-09-25'>
      <description>The "Initialize and script ActiveX controls not marked as safe" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Initialize and script ActiveX controls not marked as safe</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16344-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow binary and script behaviors" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow binary and script behaviors</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16071-3' platform='ie8' modified='2010-09-25'>
      <description>The "Launching programs and unsafe files" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Launching programs and unsafe files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16476-4' platform='ie8' modified='2010-09-25'>
      <description>The "Do not prompt for client certificate selection when no certificates or only one certificate exists." current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Do not prompt for client certificate selection when no certificates or only one certificate exists.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16280-0' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components signed with Authenticode" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Run .NET Framework-reliant components signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16190-1' platform='ie8' modified='2010-09-25'>
      <description>The "Script ActiveX controls marked safe for scripting" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Script ActiveX controls marked safe for scripting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16095-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow status bar updates via script" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow status bar updates via script</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17252-8' platform='ie8' modified='2010-09-25'>
      <description>The "Userdata persistence" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Userdata persistence</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15212-4' platform='ie8' modified='2010-09-25'>
      <description>The "Software channel permissions" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Software channel permissions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16155-4' platform='ie8' modified='2010-09-25'>
      <description>The "Java permissions" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Java permissions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15204-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to open windows without address or status bars" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow websites to open windows without address or status bars</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15567-1' platform='ie8' modified='2010-09-25'>
      <description>The "Launching applications and files in an IFRAME" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Launching applications and files in an IFRAME</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16325-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow installation of desktop items" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow installation of desktop items</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15966-5' platform='ie8' modified='2010-09-25'>
      <description>The "Access data sources across domains" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Access data sources across domains</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16291-7' platform='ie8' modified='2010-09-25'>
      <description>The "Initialize and script ActiveX controls not marked as safe" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Initialize and script ActiveX controls not marked as safe</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15975-6' platform='ie8' modified='2010-09-25'>
      <description>The "Use Pop-up Blocker" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Use Pop-up Blocker</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15678-6' platform='ie8' modified='2010-09-25'>
      <description>The "Userdata persistence" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Userdata persistence</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15243-9' platform='ie8' modified='2010-09-25'>
      <description>The "Java permissions" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Java permissions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16080-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow file downloads" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow file downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15935-0' platform='ie8' modified='2010-09-25'>
      <description>The "Loose XAML files" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Loose XAML files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15992-1' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components signed with Authenticode" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Run .NET Framework-reliant components signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16331-1' platform='ie8' modified='2010-09-25'>
      <description>The "Run ActiveX controls and plugins" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Run ActiveX controls and plugins</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16075-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to prompt for information using scripted windows" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow websites to prompt for information using scripted windows</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16311-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow Scriptlets" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow Scriptlets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17231-2' platform='ie8' modified='2010-09-25'>
      <description>The "Download unsigned ActiveX controls" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Download unsigned ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15722-2' platform='ie8' modified='2010-09-25'>
      <description>The "Include local directory path when uploading files to a server" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Include local directory path when uploading files to a server</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15742-0' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components signed with Authenticode" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Run .NET Framework-reliant components signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16448-3' platform='ie8' modified='2010-09-25'>
      <description>The "XPS documents" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\XPS documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15984-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow status bar updates via script" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow status bar updates via script</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16134-9' platform='ie8' modified='2010-09-25'>
      <description>The "Userdata persistence" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Userdata persistence</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16926-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow cut, copy or paste operations from the clipboard via script" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow cut, copy or paste operations from the clipboard via script</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16272-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow binary and script behaviors" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow binary and script behaviors</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16473-1' platform='ie8' modified='2010-09-25'>
      <description>The "Include local directory path when uploading files to a server" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Include local directory path when uploading files to a server</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16450-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active scripting" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow active scripting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17062-1' platform='ie8' modified='2010-09-25'>
      <description>The "Turn Off First-Run Opt-In" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Turn Off First-Run Opt-In</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15812-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow drag and drop or copy and paste files" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow drag and drop or copy and paste files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16265-1' platform='ie8' modified='2010-09-25'>
      <description>The "XAML browser applications" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\XAML browser applications</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16200-8' platform='ie8' modified='2010-09-25'>
      <description>The "Script ActiveX controls marked safe for scripting" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Script ActiveX controls marked safe for scripting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15912-9' platform='ie8' modified='2010-09-25'>
      <description>The "Launching programs and unsafe files" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Launching programs and unsafe files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16065-5' platform='ie8' modified='2010-09-25'>
      <description>The "Navigate windows and frames across different domains" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Navigate windows and frames across different domains</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15816-2' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for ActiveX controls" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Automatic prompting for ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16346-9' platform='ie8' modified='2010-09-25'>
      <description>The "Only allow approved domains to use ActiveX controls without prompt" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Only allow approved domains to use ActiveX controls without prompt</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16062-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active scripting" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow active scripting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17077-9' platform='ie8' modified='2010-09-25'>
      <description>The "Submit non-encrypted form data" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Submit non-encrypted form data</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15638-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow META REFRESH" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow META REFRESH</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17243-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow installation of desktop items" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow installation of desktop items</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16486-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow drag and drop or copy and paste files" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow drag and drop or copy and paste files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16417-8' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Cross-Site Scripting (XSS) Filter" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Turn on Cross-Site Scripting (XSS) Filter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15463-3' platform='ie8' modified='2010-09-25'>
      <description>The "Logon options" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Logon options</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16035-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active scripting" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow active scripting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16055-6' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Cross-Site Scripting (XSS) Filter" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Turn on Cross-Site Scripting (XSS) Filter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16732-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow drag and drop or copy and paste files" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow drag and drop or copy and paste files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16501-9' platform='ie8' modified='2010-09-25'>
      <description>The "Loose XAML files" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Loose XAML files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16307-1' platform='ie8' modified='2010-09-25'>
      <description>The "Use SmartScreen Filter" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Use SmartScreen Filter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16580-3' platform='ie8' modified='2010-09-25'>
      <description>The "Run ActiveX controls and plugins" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Run ActiveX controls and plugins</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15703-2' platform='ie8' modified='2010-09-25'>
      <description>The "Use Pop-up Blocker" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Use Pop-up Blocker</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16481-4' platform='ie8' modified='2010-09-25'>
      <description>The "Turn Off First-Run Opt-In" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Turn Off First-Run Opt-In</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17247-8' platform='ie8' modified='2010-09-25'>
      <description>The "Download signed ActiveX controls" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Download signed ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16556-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow cut, copy or paste operations from the clipboard via script" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow cut, copy or paste operations from the clipboard via script</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15036-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow installation of desktop items" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow installation of desktop items</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16482-2' platform='ie8' modified='2010-09-25'>
      <description>The "XAML browser applications" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\XAML browser applications</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16442-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow drag and drop or copy and paste files" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow drag and drop or copy and paste files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15981-4' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components signed with Authenticode" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Run .NET Framework-reliant components signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17146-2' platform='ie8' modified='2010-09-25'>
      <description>The "Scripting of Java applets" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Scripting of Java applets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16949-0' platform='ie8' modified='2010-09-25'>
      <description>The "Include local directory path when uploading files to a server" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Include local directory path when uploading files to a server</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15525-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to prompt for information using scripted windows" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow websites to prompt for information using scripted windows</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17021-7' platform='ie8' modified='2010-09-25'>
      <description>The "Only allow approved domains to use ActiveX controls without prompt" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Only allow approved domains to use ActiveX controls without prompt</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15755-2' platform='ie8' modified='2010-09-25'>
      <description>The "Scripting of Java applets" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Scripting of Java applets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17177-7' platform='ie8' modified='2010-09-25'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Web sites in less privileged Web content zones can navigate into this zone</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15754-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow scripting of Internet Explorer web browser control" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16213-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow font downloads" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow font downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16352-7' platform='ie8' modified='2010-09-25'>
      <description>The "XAML browser applications" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\XAML browser applications</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15778-4' platform='ie8' modified='2010-09-25'>
      <description>The "Submit non-encrypted form data" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Submit non-encrypted form data</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16970-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to prompt for information using scripted windows" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow websites to prompt for information using scripted windows</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15324-7' platform='ie8' modified='2010-09-25'>
      <description>The "Disable .NET Framework Setup" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Disable .NET Framework Setup</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15942-6' platform='ie8' modified='2010-09-25'>
      <description>The "XPS documents" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\XPS documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16217-2' platform='ie8' modified='2010-09-25'>
      <description>The "Use Pop-up Blocker" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Use Pop-up Blocker</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15574-7' platform='ie8' modified='2010-09-25'>
      <description>The "Run ActiveX controls and plugins" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Run ActiveX controls and plugins</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16333-7' platform='ie8' modified='2010-09-25'>
      <description>The "Download signed ActiveX controls" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Download signed ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15432-8' platform='ie8' modified='2010-09-25'>
      <description>The "Open files based on content, not file extension" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Open files based on content, not file extension</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16446-7' platform='ie8' modified='2010-09-25'>
      <description>The "Launching applications and files in an IFRAME" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Launching applications and files in an IFRAME</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16045-7' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for ActiveX controls" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Automatic prompting for ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17066-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow video and animation on a Web page that uses a legacy media player" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow video and animation on a Web page that uses a legacy media player</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15233-0' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for file downloads" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Automatic prompting for file downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16222-2' platform='ie8' modified='2010-09-25'>
      <description>The "Access data sources across domains" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Access data sources across domains</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15997-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow file downloads" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow file downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15941-8' platform='ie8' modified='2010-09-25'>
      <description>The "Loose XAML files" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Loose XAML files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15634-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow file downloads" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow file downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15228-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow video and animation on a Web page that uses a legacy media player" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow video and animation on a Web page that uses a legacy media player</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15301-5' platform='ie8' modified='2010-09-25'>
      <description>The "Navigate windows and frames across different domains" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Navigate windows and frames across different domains</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15679-4' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for ActiveX controls" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Automatic prompting for ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16221-4' platform='ie8' modified='2010-09-25'>
      <description>The "Navigate windows and frames across different domains" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Navigate windows and frames across different domains</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15939-2' platform='ie8' modified='2010-09-25'>
      <description>The "XPS documents" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\XPS documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16390-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow file downloads" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow file downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17225-4' platform='ie8' modified='2010-09-25'>
      <description>The "Launching applications and files in an IFRAME" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Launching applications and files in an IFRAME</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16339-4' platform='ie8' modified='2010-09-25'>
      <description>The "Navigate windows and frames across different domains" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Navigate windows and frames across different domains</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16305-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow video and animation on a Web page that uses a legacy media player" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow video and animation on a Web page that uses a legacy media player</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16321-2' platform='ie8' modified='2010-09-25'>
      <description>The "Download signed ActiveX controls" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Download signed ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15551-5' platform='ie8' modified='2010-09-25'>
      <description>The "Userdata persistence" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Userdata persistence</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16453-3' platform='ie8' modified='2010-09-25'>
      <description>The "Run ActiveX controls and plugins" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Run ActiveX controls and plugins</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16258-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow status bar updates via script" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow status bar updates via script</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15322-1' platform='ie8' modified='2010-09-25'>
      <description>The "Use SmartScreen Filter" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Use SmartScreen Filter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16386-5' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Protected Mode" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Turn on Protected Mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16495-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow script-initiated windows without size or position constraints" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow script-initiated windows without size or position constraints</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17118-1' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for ActiveX controls" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Automatic prompting for ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16415-2' platform='ie8' modified='2010-09-25'>
      <description>The "XPS documents" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\XPS documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17180-1' platform='ie8' modified='2010-09-25'>
      <description>The "Do not prompt for client certificate selection when no certificates or only one certificate exists." current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Do not prompt for client certificate selection when no certificates or only one certificate exists.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16366-7' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for ActiveX controls" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Automatic prompting for ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16223-0' platform='ie8' modified='2010-09-25'>
      <description>The "Turn Off First-Run Opt-In" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Turn Off First-Run Opt-In</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15506-9' platform='ie8' modified='2010-09-25'>
      <description>The "Download unsigned ActiveX controls" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Download unsigned ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15626-5' platform='ie8' modified='2010-09-25'>
      <description>The "Access data sources across domains" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Access data sources across domains</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16560-5' platform='ie8' modified='2010-09-25'>
      <description>The "Open files based on content, not file extension" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Open files based on content, not file extension</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17141-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow META REFRESH" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow META REFRESH</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16399-8' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components not signed with Authenticode" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Run .NET Framework-reliant components not signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16326-1' platform='ie8' modified='2010-09-25'>
      <description>The "Display mixed content" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Display mixed content</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15100-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow scripting of Internet Explorer web browser control" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15318-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow cut, copy or paste operations from the clipboard via script" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow cut, copy or paste operations from the clipboard via script</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17032-4' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Protected Mode" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Turn on Protected Mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16198-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow META REFRESH" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow META REFRESH</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15255-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow cut, copy or paste operations from the clipboard via script" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow cut, copy or paste operations from the clipboard via script</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17078-7' platform='ie8' modified='2010-09-25'>
      <description>The "Software channel permissions" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Software channel permissions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15513-5' platform='ie8' modified='2010-09-25'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Web sites in less privileged Web content zones can navigate into this zone</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16455-8' platform='ie8' modified='2010-09-25'>
      <description>The "Use SmartScreen Filter" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Use SmartScreen Filter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15539-0' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components not signed with Authenticode" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Run .NET Framework-reliant components not signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15603-4' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Protected Mode" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Turn on Protected Mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16576-1' platform='ie8' modified='2010-09-25'>
      <description>The "Use SmartScreen Filter" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Use SmartScreen Filter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15328-8' platform='ie8' modified='2010-09-25'>
      <description>The "Display mixed content" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Display mixed content</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16412-9' platform='ie8' modified='2010-09-25'>
      <description>The "Launching applications and files in an IFRAME" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Launching applications and files in an IFRAME</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16420-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow scripting of Internet Explorer web browser control" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16761-9' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for file downloads" current user setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Automatic prompting for file downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16041-6' platform='ie8' modified='2010-09-25'>
      <description>The "Access data sources across domains" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Access data sources across domains</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15646-3' platform='ie8' modified='2010-09-25'>
      <description>The "Logon options" current user setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Logon options</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16011-9' platform='ie8' modified='2010-09-25'>
      <description>The "Script ActiveX controls marked safe for scripting" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Script ActiveX controls marked safe for scripting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15632-3' platform='ie8' modified='2010-09-25'>
      <description>The "Use Pop-up Blocker" current user setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Use Pop-up Blocker</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15589-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow font downloads" current user setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow font downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16082-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow scripting of Internet Explorer web browser control" current user setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16645-4' platform='ie8' modified='2010-09-25'>
      <description>The "Restrict ActiveX Install: Internet Explorer Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Restrict ActiveX Install\Internet Explorer Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15869-1' platform='ie8' modified='2010-09-25'>
      <description>The "Restrict ActiveX Install: All Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Restrict ActiveX Install\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_ACTIVEXINSTALL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16491-3' platform='ie8' modified='2010-09-25'>
      <description>The "Restrict ActiveX Install: Process List" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Restrict ActiveX Install\Process List</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16032-5' platform='ie8' modified='2010-09-25'>
      <description>The "Enable cut, copy or paste operations from the clipboard if URLACTION_SCRIPT_PASTE is set to Prompt: Internet Explorer Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Application Compatibility\Enable cut, copy or paste operations from the clipboard if URLACTION_SCRIPT_PASTE is set to Prompt\Internet Explorer Processes</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\Feature_Enable_Script_Paste_URLAction_If_Prompt</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15508-5' platform='ie8' modified='2010-09-25'>
      <description>The "Enable cut, copy or paste operations from the clipboard if URLACTION_SCRIPT_PASTE is set to Prompt: All Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Application Compatibility\Enable cut, copy or paste operations from the clipboard if URLACTION_SCRIPT_PASTE is set to Prompt\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\Feature_Enable_Script_Paste_URLAction_If_Prompt</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15781-8' platform='ie8' modified='2010-09-25'>
      <description>The "Enable cut, copy or paste operations from the clipboard if URLACTION_SCRIPT_PASTE is set to Prompt: Process List" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Application Compatibility\Enable cut, copy or paste operations from the clipboard if URLACTION_SCRIPT_PASTE is set to Prompt\Process List</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15482-3' platform='ie8' modified='2010-09-25'>
      <description>The "Object Caching Protection: Process List" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Object Caching Protection\Process List</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15483-1' platform='ie8' modified='2010-09-25'>
      <description>The "Object Caching Protection: Internet Explorer Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Object Caching Protection\Internet Explorer Processes</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15487-2' platform='ie8' modified='2010-09-25'>
      <description>The "Object Caching Protection: All Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Object Caching Protection\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16683-5' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent setting of the code download path for each machine" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Corporate Settings\Code Download\Prevent setting of the code download path for each machine</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16121-6' platform='ie8' modified='2010-09-25'>
      <description>The "Navigate windows and frames across different domains" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Navigate windows and frames across different domains</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15177-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn Off First-Run Opt-In" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Turn Off First-Run Opt-In</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16081-2' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for ActiveX controls" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Automatic prompting for ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16085-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow video and animation on a Web page that uses a legacy media player" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow video and animation on a Web page that uses a legacy media player</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15787-5' platform='ie8' modified='2010-09-25'>
      <description>The "Software channel permissions" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Software channel permissions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15961-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow binary and script behaviors" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow binary and script behaviors</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15989-7' platform='ie8' modified='2010-09-25'>
      <description>The "Only allow approved domains to use ActiveX controls without prompt" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Only allow approved domains to use ActiveX controls without prompt</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15215-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow Scriptlets" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow Scriptlets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15446-8' platform='ie8' modified='2010-09-25'>
      <description>The "Java permissions" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Java permissions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15748-7' platform='ie8' modified='2010-09-25'>
      <description>The "Download signed ActiveX controls" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Download signed ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15479-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow installation of desktop items" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow installation of desktop items</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15162-1' platform='ie8' modified='2010-09-25'>
      <description>The "Disable .NET Framework Setup" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Disable .NET Framework Setup</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15385-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow META REFRESH" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow META REFRESH</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15171-2' platform='ie8' modified='2010-09-25'>
      <description>The "Launching programs and unsafe files" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Launching programs and unsafe files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16044-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow cut, copy or paste operations from the clipboard via script" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow cut, copy or paste operations from the clipboard via script</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15988-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Protected Mode" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Turn on Protected Mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15858-4' platform='ie8' modified='2010-09-25'>
      <description>The "Open files based on content, not file extension" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Open files based on content, not file extension</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15195-1' platform='ie8' modified='2010-09-25'>
      <description>The "Userdata persistence" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Userdata persistence</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16122-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow file downloads" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow file downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15153-0' platform='ie8' modified='2010-09-25'>
      <description>The "Run ActiveX controls and plugins" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Run ActiveX controls and plugins</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15157-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active content over restricted protocols to access my computer" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow active content over restricted protocols to access my computer</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16116-6' platform='ie8' modified='2010-09-25'>
      <description>The "Script ActiveX controls marked safe for scripting" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Script ActiveX controls marked safe for scripting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15800-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow drag and drop or copy and paste files" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow drag and drop or copy and paste files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16108-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow scripting of Internet Explorer web browser control" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15902-0' platform='ie8' modified='2010-09-25'>
      <description>The "Include local directory path when uploading files to a server" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Include local directory path when uploading files to a server</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16025-9' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components signed with Authenticode" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Run .NET Framework-reliant components signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15761-0' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Cross-Site Scripting (XSS) Filter" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Turn on Cross-Site Scripting (XSS) Filter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15668-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow font downloads" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow font downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16064-8' platform='ie8' modified='2010-09-25'>
      <description>The "XPS documents" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\XPS documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15196-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active scripting" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow active scripting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16054-9' platform='ie8' modified='2010-09-25'>
      <description>The "Do not prompt for client certificate selection when no certificates or only one certificate exists." current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Do not prompt for client certificate selection when no certificates or only one certificate exists.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15193-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to prompt for information using scripted windows" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow websites to prompt for information using scripted windows</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15757-8' platform='ie8' modified='2010-09-25'>
      <description>The "Access data sources across domains" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Access data sources across domains</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16144-8' platform='ie8' modified='2010-09-25'>
      <description>The "Display mixed content" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Display mixed content</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15241-3' platform='ie8' modified='2010-09-25'>
      <description>The "XAML browser applications" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\XAML browser applications</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16076-2' platform='ie8' modified='2010-09-25'>
      <description>The "Use SmartScreen Filter" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Use SmartScreen Filter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16003-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow script-initiated windows without size or position constraints" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow script-initiated windows without size or position constraints</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15602-6' platform='ie8' modified='2010-09-25'>
      <description>The "Scripting of Java applets" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Scripting of Java applets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16031-7' platform='ie8' modified='2010-09-25'>
      <description>The "Logon options" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Logon options</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16126-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow status bar updates via script" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow status bar updates via script</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16140-6' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components not signed with Authenticode" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Run .NET Framework-reliant components not signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16100-0' platform='ie8' modified='2010-09-25'>
      <description>The "Submit non-encrypted form data" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Submit non-encrypted form data</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15185-2' platform='ie8' modified='2010-09-25'>
      <description>The "Launching applications and files in an IFRAME" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Launching applications and files in an IFRAME</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16099-4' platform='ie8' modified='2010-09-25'>
      <description>The "Loose XAML files" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Loose XAML files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15880-8' platform='ie8' modified='2010-09-25'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Web sites in less privileged Web content zones can navigate into this zone</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16059-8' platform='ie8' modified='2010-09-25'>
      <description>The "Download unsigned ActiveX controls" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Download unsigned ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15565-5' platform='ie8' modified='2010-09-25'>
      <description>The "Use Pop-up Blocker" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Use Pop-up Blocker</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15752-9' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for file downloads" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Automatic prompting for file downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15237-1' platform='ie8' modified='2010-09-25'>
      <description>The "Initialize and script ActiveX controls not marked as safe" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Initialize and script ActiveX controls not marked as safe</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15959-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to open windows without address or status bars" current user setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow websites to open windows without address or status bars</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16692-6' platform='ie8' modified='2010-09-25'>
      <description>The "Network Protocol Lockdown: Internet Explorer Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Network Protocol Lockdown\Internet Explorer Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16696-7' platform='ie8' modified='2010-09-25'>
      <description>The "Network Protocol Lockdown: All Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Network Protocol Lockdown\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16670-2' platform='ie8' modified='2010-09-25'>
      <description>The "Network Protocol Lockdown: Process List" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Network Protocol Lockdown\Process List</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16648-8' platform='ie8' modified='2010-09-25'>
      <description>The "Consistent Mime Handling: All Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Consistent Mime Handling\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16653-8' platform='ie8' modified='2010-09-25'>
      <description>The "Consistent Mime Handling: Process List" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Consistent Mime Handling\Process List</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17095-1' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for ActiveX controls" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Automatic prompting for ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17092-8' platform='ie8' modified='2010-09-25'>
      <description>The "Submit non-encrypted form data" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Submit non-encrypted form data</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16988-8' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for file downloads" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Automatic prompting for file downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17014-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to open windows without address or status bars" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow websites to open windows without address or status bars</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17054-8' platform='ie8' modified='2010-09-25'>
      <description>The "Display mixed content" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Display mixed content</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17076-1' platform='ie8' modified='2010-09-25'>
      <description>The "Include local directory path when uploading files to a server" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Include local directory path when uploading files to a server</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17023-3' platform='ie8' modified='2010-09-25'>
      <description>The "Use Pop-up Blocker" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Use Pop-up Blocker</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17006-8' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components signed with Authenticode" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Run .NET Framework-reliant components signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16611-6' platform='ie8' modified='2010-09-25'>
      <description>The "XPS documents" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\XPS documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16734-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow file downloads" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow file downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16196-8' platform='ie8' modified='2010-09-25'>
      <description>The "Logon options" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Logon options</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17107-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow script-initiated windows without size or position constraints" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow script-initiated windows without size or position constraints</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16817-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to prompt for information using scripted windows" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow websites to prompt for information using scripted windows</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16159-6' platform='ie8' modified='2010-09-25'>
      <description>The "Java permissions" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Java permissions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16494-7' platform='ie8' modified='2010-09-25'>
      <description>The "Open files based on content, not file extension" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Open files based on content, not file extension</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16118-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow binary and script behaviors" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow binary and script behaviors</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16905-2' platform='ie8' modified='2010-09-25'>
      <description>The "Userdata persistence" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Userdata persistence</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17073-8' platform='ie8' modified='2010-09-25'>
      <description>The "Access data sources across domains" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Access data sources across domains</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16974-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow video and animation on a Web page that uses a legacy media player" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow video and animation on a Web page that uses a legacy media player</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17063-9' platform='ie8' modified='2010-09-25'>
      <description>The "Use SmartScreen Filter" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Use SmartScreen Filter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16154-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow drag and drop or copy and paste files" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow drag and drop or copy and paste files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17010-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active scripting" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow active scripting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16878-1' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Cross-Site Scripting (XSS) Filter" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Turn on Cross-Site Scripting (XSS) Filter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16156-2' platform='ie8' modified='2010-09-25'>
      <description>The "Navigate windows and frames across different domains" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Navigate windows and frames across different domains</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16496-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow cut, copy or paste operations from the clipboard via script" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow cut, copy or paste operations from the clipboard via script</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16240-4' platform='ie8' modified='2010-09-25'>
      <description>The "Download signed ActiveX controls" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Download signed ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16209-9' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components not signed with Authenticode" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Run .NET Framework-reliant components not signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17079-5' platform='ie8' modified='2010-09-25'>
      <description>The "Do not prompt for client certificate selection when no certificates or only one certificate exists." current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Do not prompt for client certificate selection when no certificates or only one certificate exists.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16135-6' platform='ie8' modified='2010-09-25'>
      <description>The "Software channel permissions" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Software channel permissions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16738-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active content over restricted protocols to access my computer" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow active content over restricted protocols to access my computer</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16855-9' platform='ie8' modified='2010-09-25'>
      <description>The "Disable .NET Framework Setup" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Disable .NET Framework Setup</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16139-8' platform='ie8' modified='2010-09-25'>
      <description>The "Loose XAML files" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Loose XAML files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17124-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow META REFRESH" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow META REFRESH</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17085-2' platform='ie8' modified='2010-09-25'>
      <description>The "Launching applications and files in an IFRAME" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Launching applications and files in an IFRAME</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16107-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow installation of desktop items" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow installation of desktop items</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17088-6' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Protected Mode" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Turn on Protected Mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16109-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow status bar updates via script" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow status bar updates via script</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16709-8' platform='ie8' modified='2010-09-25'>
      <description>The "Initialize and script ActiveX controls not marked as safe" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Initialize and script ActiveX controls not marked as safe</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16860-9' platform='ie8' modified='2010-09-25'>
      <description>The "Launching programs and unsafe files" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Launching programs and unsafe files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16153-9' platform='ie8' modified='2010-09-25'>
      <description>The "Only allow approved domains to use ActiveX controls without prompt" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Only allow approved domains to use ActiveX controls without prompt</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16832-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow font downloads" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow font downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16130-7' platform='ie8' modified='2010-09-25'>
      <description>The "Scripting of Java applets" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Scripting of Java applets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17050-6' platform='ie8' modified='2010-09-25'>
      <description>The "Download unsigned ActiveX controls" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Download unsigned ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16152-1' platform='ie8' modified='2010-09-25'>
      <description>The "Run ActiveX controls and plugins" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Run ActiveX controls and plugins</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17117-3' platform='ie8' modified='2010-09-25'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Web sites in less privileged Web content zones can navigate into this zone</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17059-7' platform='ie8' modified='2010-09-25'>
      <description>The "XAML browser applications" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\XAML browser applications</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16503-5' platform='ie8' modified='2010-09-25'>
      <description>The "Turn Off First-Run Opt-In" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Turn Off First-Run Opt-In</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16507-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow Scriptlets" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Allow Scriptlets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17099-3' platform='ie8' modified='2010-09-25'>
      <description>The "Script ActiveX controls marked safe for scripting" current user setting should be configured correctly for the Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone\Script ActiveX controls marked safe for scripting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16336-0' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent configuration of search from the Address bar" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Advanced settings\Searching\Prevent configuration of search from the Address bar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15739-6' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on the Internet Connection Wizard Auto Detect" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Advanced settings\Internet Connection Wizard Settings\Turn on the Internet Connection Wizard Auto Detect</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Connection Wizard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16925-0' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off sending URLs as UTF-8 (requires restart)" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\URL Encoding\Turn off sending URLs as UTF-8 (requires restart)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16089-5' platform='ie8' modified='2010-09-25'>
      <description>The "Add-on List" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Add-on Management\Add-on List</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Ext</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16711-4' platform='ie8' modified='2010-09-25'>
      <description>The "Deny all add-ons unless specifically allowed in the Add-on List" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Add-on Management\Deny all add-ons unless specifically allowed in the Add-on List</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Ext</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16847-6' platform='ie8' modified='2010-09-25'>
      <description>The "Add-on Management: All Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Add-on Management\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16341-0' platform='ie8' modified='2010-09-25'>
      <description>The "Add-on Management: Process List" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Add-on Management\Process List</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16125-7' platform='ie8' modified='2010-09-25'>
      <description>The "Mime Sniffing Safety Feature: Process List" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Mime Sniffing Safety Feature\Process List</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16367-5' platform='ie8' modified='2010-09-25'>
      <description>The "Mime Sniffing Safety Feature: Internet Explorer Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Mime Sniffing Safety Feature\Internet Explorer Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16239-6' platform='ie8' modified='2010-09-25'>
      <description>The "Mime Sniffing Safety Feature: All Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Mime Sniffing Safety Feature\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15947-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow binary and script behaviors" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow binary and script behaviors</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16904-5' platform='ie8' modified='2010-09-25'>
      <description>The "Launching applications and files in an IFRAME" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Launching applications and files in an IFRAME</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16659-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow cut, copy or paste operations from the clipboard via script" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow cut, copy or paste operations from the clipboard via script</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16251-1' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Protected Mode" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Turn on Protected Mode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16026-7' platform='ie8' modified='2010-09-25'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Web sites in less privileged Web content zones can navigate into this zone</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16864-1' platform='ie8' modified='2010-09-25'>
      <description>The "Userdata persistence" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Userdata persistence</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16046-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow font downloads" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow font downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16826-0' platform='ie8' modified='2010-09-25'>
      <description>The "Loose XAML files" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Loose XAML files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15190-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow file downloads" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow file downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16243-8' platform='ie8' modified='2010-09-25'>
      <description>The "Download unsigned ActiveX controls" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Download unsigned ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16230-5' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Cross-Site Scripting (XSS) Filter" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Turn on Cross-Site Scripting (XSS) Filter</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16637-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow Scriptlets" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow Scriptlets</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16347-7' platform='ie8' modified='2010-09-25'>
      <description>The "Loose XAML files" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Loose XAML files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15719-8' platform='ie8' modified='2010-09-25'>
      <description>The "Script ActiveX controls marked safe for scripting" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Script ActiveX controls marked safe for scripting</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16565-4' platform='ie8' modified='2010-09-25'>
      <description>The "Navigate windows and frames across different domains" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Navigate windows and frames across different domains</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16719-7' platform='ie8' modified='2010-09-25'>
      <description>The "Software channel permissions" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Software channel permissions</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16178-6' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Cross-Site Scripting (XSS) Filter" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Turn on Cross-Site Scripting (XSS) Filter</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16667-8' platform='ie8' modified='2010-09-25'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Web sites in less privileged Web content zones can navigate into this zone</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16650-4' platform='ie8' modified='2010-09-25'>
      <description>The "Use Pop-up Blocker" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Use Pop-up Blocker</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15807-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow cut, copy or paste operations from the clipboard via script" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow cut, copy or paste operations from the clipboard via script</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16425-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow cut, copy or paste operations from the clipboard via script" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow cut, copy or paste operations from the clipboard via script</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16539-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow status bar updates via script" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow status bar updates via script</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16857-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow binary and script behaviors" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow binary and script behaviors</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16807-0' platform='ie8' modified='2010-09-25'>
      <description>The "Logon options" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Logon options</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16233-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Cross-Site Scripting (XSS) Filter" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Turn on Cross-Site Scripting (XSS) Filter</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15949-1' platform='ie8' modified='2010-09-25'>
      <description>The "Turn Off First-Run Opt-In" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Turn Off First-Run Opt-In</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14981-5' platform='ie8' modified='2010-09-25'>
      <description>The "Logon options" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Logon options</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16160-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow binary and script behaviors" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow binary and script behaviors</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16039-0' platform='ie8' modified='2010-09-25'>
      <description>The "Script ActiveX controls marked safe for scripting" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Script ActiveX controls marked safe for scripting</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15710-7' platform='ie8' modified='2010-09-25'>
      <description>The "Userdata persistence" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Userdata persistence</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16668-6' platform='ie8' modified='2010-09-25'>
      <description>The "Disable .NET Framework Setup" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Disable .NET Framework Setup</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16581-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow scripting of Internet Explorer web browser control" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15682-8' platform='ie8' modified='2010-09-25'>
      <description>The "Download signed ActiveX controls" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Download signed ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16614-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow installation of desktop items" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow installation of desktop items</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16543-1' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for file downloads" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Automatic prompting for file downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16959-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to prompt for information using scripted windows" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow websites to prompt for information using scripted windows</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16086-1' platform='ie8' modified='2010-09-25'>
      <description>The "Open files based on content, not file extension" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Open files based on content, not file extension</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15798-2' platform='ie8' modified='2010-09-25'>
      <description>The "Download signed ActiveX controls" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Download signed ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16601-7' platform='ie8' modified='2010-09-25'>
      <description>The "Loose XAML files" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Loose XAML files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16803-9' platform='ie8' modified='2010-09-25'>
      <description>The "Software channel permissions" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Software channel permissions</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15811-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Protected Mode" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Turn on Protected Mode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16468-1' platform='ie8' modified='2010-09-25'>
      <description>The "Submit non-encrypted form data" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Submit non-encrypted form data</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16616-5' platform='ie8' modified='2010-09-25'>
      <description>The "Software channel permissions" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Software channel permissions</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15897-2' platform='ie8' modified='2010-09-25'>
      <description>The "XAML browser applications" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\XAML browser applications</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16454-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to prompt for information using scripted windows" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow websites to prompt for information using scripted windows</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16445-9' platform='ie8' modified='2010-09-25'>
      <description>The "Initialize and script ActiveX controls not marked as safe" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Initialize and script ActiveX controls not marked as safe</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16548-0' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for ActiveX controls" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Automatic prompting for ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15080-5' platform='ie8' modified='2010-09-25'>
      <description>The "Display mixed content" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Display mixed content</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15644-8' platform='ie8' modified='2010-09-25'>
      <description>The "Launching applications and files in an IFRAME" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Launching applications and files in an IFRAME</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16029-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active scripting" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow active scripting</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16733-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow font downloads" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow font downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15728-9' platform='ie8' modified='2010-09-25'>
      <description>The "Disable .NET Framework Setup" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Disable .NET Framework Setup</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15304-9' platform='ie8' modified='2010-09-25'>
      <description>The "Initialize and script ActiveX controls not marked as safe" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Initialize and script ActiveX controls not marked as safe</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16535-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active scripting" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow active scripting</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16519-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to open windows without address or status bars" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow websites to open windows without address or status bars</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15653-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow drag and drop or copy and paste files" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow drag and drop or copy and paste files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15842-8' platform='ie8' modified='2010-09-25'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Web sites in less privileged Web content zones can navigate into this zone</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16947-4' platform='ie8' modified='2010-09-25'>
      <description>The "Do not prompt for client certificate selection when no certificates or only one certificate exists." machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Do not prompt for client certificate selection when no certificates or only one certificate exists.</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15906-1' platform='ie8' modified='2010-09-25'>
      <description>The "Disable .NET Framework Setup" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Disable .NET Framework Setup</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16954-0' platform='ie8' modified='2010-09-25'>
      <description>The "Logon options" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Logon options</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16876-5' platform='ie8' modified='2010-09-25'>
      <description>The "XPS documents" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\XPS documents</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15970-7' platform='ie8' modified='2010-09-25'>
      <description>The "Launching programs and unsafe files" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Launching programs and unsafe files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16793-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow binary and script behaviors" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow binary and script behaviors</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16471-5' platform='ie8' modified='2010-09-25'>
      <description>The "Scripting of Java applets" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Scripting of Java applets</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16499-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow META REFRESH" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow META REFRESH</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15864-2' platform='ie8' modified='2010-09-25'>
      <description>The "Only allow approved domains to use ActiveX controls without prompt" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Only allow approved domains to use ActiveX controls without prompt</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15847-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active scripting" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow active scripting</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16841-9' platform='ie8' modified='2010-09-25'>
      <description>The "Disable .NET Framework Setup" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Disable .NET Framework Setup</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16077-0' platform='ie8' modified='2010-09-25'>
      <description>The "Download unsigned ActiveX controls" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Download unsigned ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15012-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow status bar updates via script" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow status bar updates via script</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15666-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow Scriptlets" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow Scriptlets</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16104-2' platform='ie8' modified='2010-09-25'>
      <description>The "Include local directory path when uploading files to a server" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Include local directory path when uploading files to a server</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15960-8' platform='ie8' modified='2010-09-25'>
      <description>The "Download unsigned ActiveX controls" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Download unsigned ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16009-3' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for ActiveX controls" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Automatic prompting for ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16895-5' platform='ie8' modified='2010-09-25'>
      <description>The "Open files based on content, not file extension" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Open files based on content, not file extension</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16225-5' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Protected Mode" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Turn on Protected Mode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16205-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow file downloads" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow file downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16546-4' platform='ie8' modified='2010-09-25'>
      <description>The "Launching applications and files in an IFRAME" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Launching applications and files in an IFRAME</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16932-6' platform='ie8' modified='2010-09-25'>
      <description>The "Submit non-encrypted form data" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Submit non-encrypted form data</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16891-4' platform='ie8' modified='2010-09-25'>
      <description>The "Turn Off First-Run Opt-In" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Turn Off First-Run Opt-In</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16886-4' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Cross-Site Scripting (XSS) Filter" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Turn on Cross-Site Scripting (XSS) Filter</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16179-4' platform='ie8' modified='2010-09-25'>
      <description>The "Script ActiveX controls marked safe for scripting" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Script ActiveX controls marked safe for scripting</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16246-1' platform='ie8' modified='2010-09-25'>
      <description>The "Disable .NET Framework Setup" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Disable .NET Framework Setup</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16567-0' platform='ie8' modified='2010-09-25'>
      <description>The "Userdata persistence" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Userdata persistence</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15813-9' platform='ie8' modified='2010-09-25'>
      <description>The "Launching programs and unsafe files" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Launching programs and unsafe files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15987-1' platform='ie8' modified='2010-09-25'>
      <description>The "Script ActiveX controls marked safe for scripting" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Script ActiveX controls marked safe for scripting</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16533-2' platform='ie8' modified='2010-09-25'>
      <description>The "Navigate windows and frames across different domains" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Navigate windows and frames across different domains</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16069-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow file downloads" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow file downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15934-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow video and animation on a Web page that uses a legacy media player" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow video and animation on a Web page that uses a legacy media player</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15393-2' platform='ie8' modified='2010-09-25'>
      <description>The "Open files based on content, not file extension" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Open files based on content, not file extension</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16859-1' platform='ie8' modified='2010-09-25'>
      <description>The "Do not prompt for client certificate selection when no certificates or only one certificate exists." machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Do not prompt for client certificate selection when no certificates or only one certificate exists.</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16643-9' platform='ie8' modified='2010-09-25'>
      <description>The "Initialize and script ActiveX controls not marked as safe" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Initialize and script ActiveX controls not marked as safe</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15208-2' platform='ie8' modified='2010-09-25'>
      <description>The "XAML browser applications" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\XAML browser applications</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16737-9' platform='ie8' modified='2010-09-25'>
      <description>The "Download signed ActiveX controls" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Download signed ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15596-0' platform='ie8' modified='2010-09-25'>
      <description>The "Navigate windows and frames across different domains" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Navigate windows and frames across different domains</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15909-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow cut, copy or paste operations from the clipboard via script" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow cut, copy or paste operations from the clipboard via script</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16195-0' platform='ie8' modified='2010-09-25'>
      <description>The "XPS documents" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\XPS documents</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15362-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to open windows without address or status bars" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow websites to open windows without address or status bars</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15766-9' platform='ie8' modified='2010-09-25'>
      <description>The "XAML browser applications" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\XAML browser applications</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15983-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow installation of desktop items" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow installation of desktop items</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16447-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow installation of desktop items" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow installation of desktop items</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15694-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow video and animation on a Web page that uses a legacy media player" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow video and animation on a Web page that uses a legacy media player</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16617-3' platform='ie8' modified='2010-09-25'>
      <description>The "Access data sources across domains" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Access data sources across domains</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16730-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow video and animation on a Web page that uses a legacy media player" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow video and animation on a Web page that uses a legacy media player</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15017-7' platform='ie8' modified='2010-09-25'>
      <description>The "Loose XAML files" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Loose XAML files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16229-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow installation of desktop items" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow installation of desktop items</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16784-1' platform='ie8' modified='2010-09-25'>
      <description>The "Userdata persistence" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Userdata persistence</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16043-2' platform='ie8' modified='2010-09-25'>
      <description>The "Navigate windows and frames across different domains" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Navigate windows and frames across different domains</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16729-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow META REFRESH" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow META REFRESH</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16318-8' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components not signed with Authenticode" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Run .NET Framework-reliant components not signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15915-2' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for ActiveX controls" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Automatic prompting for ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16189-3' platform='ie8' modified='2010-09-25'>
      <description>The "Display mixed content" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Display mixed content</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15600-0' platform='ie8' modified='2010-09-25'>
      <description>The "Include local directory path when uploading files to a server" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Include local directory path when uploading files to a server</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16373-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow Scriptlets" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow Scriptlets</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15957-4' platform='ie8' modified='2010-09-25'>
      <description>The "Use Pop-up Blocker" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Use Pop-up Blocker</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16854-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow installation of desktop items" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow installation of desktop items</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15952-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow scripting of Internet Explorer web browser control" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16553-0' platform='ie8' modified='2010-09-25'>
      <description>The "Open files based on content, not file extension" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Open files based on content, not file extension</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16922-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow status bar updates via script" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow status bar updates via script</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16577-9' platform='ie8' modified='2010-09-25'>
      <description>The "Launching applications and files in an IFRAME" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Launching applications and files in an IFRAME</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15639-8' platform='ie8' modified='2010-09-25'>
      <description>The "Download unsigned ActiveX controls" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Download unsigned ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15971-5' platform='ie8' modified='2010-09-25'>
      <description>The "Access data sources across domains" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Access data sources across domains</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17009-2' platform='ie8' modified='2010-09-25'>
      <description>The "Run ActiveX controls and plugins" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Run ActiveX controls and plugins</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16517-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow Scriptlets" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow Scriptlets</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16943-3' platform='ie8' modified='2010-09-25'>
      <description>The "Download signed ActiveX controls" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Download signed ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16224-8' platform='ie8' modified='2010-09-25'>
      <description>The "Display mixed content" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Display mixed content</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16004-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow video and animation on a Web page that uses a legacy media player" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow video and animation on a Web page that uses a legacy media player</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16724-7' platform='ie8' modified='2010-09-25'>
      <description>The "Use Pop-up Blocker" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Use Pop-up Blocker</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16092-9' platform='ie8' modified='2010-09-25'>
      <description>The "Logon options" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Logon options</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16595-1' platform='ie8' modified='2010-09-25'>
      <description>The "Userdata persistence" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Userdata persistence</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16274-3' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for ActiveX controls" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Automatic prompting for ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16824-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to open windows without address or status bars" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow websites to open windows without address or status bars</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16607-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow font downloads" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow font downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16571-2' platform='ie8' modified='2010-09-25'>
      <description>The "XPS documents" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\XPS documents</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16963-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow video and animation on a Web page that uses a legacy media player" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow video and animation on a Web page that uses a legacy media player</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16188-5' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components signed with Authenticode" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Run .NET Framework-reliant components signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16105-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn Off First-Run Opt-In" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Turn Off First-Run Opt-In</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15948-3' platform='ie8' modified='2010-09-25'>
      <description>The "Scripting of Java applets" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Scripting of Java applets</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16985-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active scripting" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow active scripting</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16096-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow status bar updates via script" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow status bar updates via script</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16830-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow status bar updates via script" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow status bar updates via script</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16110-9' platform='ie8' modified='2010-09-25'>
      <description>The "Launching programs and unsafe files" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Launching programs and unsafe files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16957-3' platform='ie8' modified='2010-09-25'>
      <description>The "Display mixed content" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Display mixed content</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15851-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to prompt for information using scripted windows" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow websites to prompt for information using scripted windows</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16490-5' platform='ie8' modified='2010-09-25'>
      <description>The "Script ActiveX controls marked safe for scripting" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Script ActiveX controls marked safe for scripting</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16935-9' platform='ie8' modified='2010-09-25'>
      <description>The "XAML browser applications" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\XAML browser applications</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15642-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow file downloads" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow file downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15892-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active scripting" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow active scripting</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16320-4' platform='ie8' modified='2010-09-25'>
      <description>The "Download unsigned ActiveX controls" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Download unsigned ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16635-5' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components not signed with Authenticode" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Run .NET Framework-reliant components not signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15732-1' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Cross-Site Scripting (XSS) Filter" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Turn on Cross-Site Scripting (XSS) Filter</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16392-3' platform='ie8' modified='2010-09-25'>
      <description>The "Display mixed content" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Display mixed content</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15956-6' platform='ie8' modified='2010-09-25'>
      <description>The "Software channel permissions" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Software channel permissions</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16972-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow binary and script behaviors" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow binary and script behaviors</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15954-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow META REFRESH" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow META REFRESH</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16631-4' platform='ie8' modified='2010-09-25'>
      <description>The "Initialize and script ActiveX controls not marked as safe" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Initialize and script ActiveX controls not marked as safe</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16228-9' platform='ie8' modified='2010-09-25'>
      <description>The "Use Pop-up Blocker" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Use Pop-up Blocker</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15891-5' platform='ie8' modified='2010-09-25'>
      <description>The "XPS documents" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\XPS documents</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16782-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow META REFRESH" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow META REFRESH</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16371-7' platform='ie8' modified='2010-09-25'>
      <description>The "Scripting of Java applets" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Scripting of Java applets</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16828-6' platform='ie8' modified='2010-09-25'>
      <description>The "Scripting of Java applets" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Scripting of Java applets</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15944-2' platform='ie8' modified='2010-09-25'>
      <description>The "Run ActiveX controls and plugins" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Run ActiveX controls and plugins</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16600-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow script-initiated windows without size or position constraints" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow script-initiated windows without size or position constraints</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15901-2' platform='ie8' modified='2010-09-25'>
      <description>The "Do not prompt for client certificate selection when no certificates or only one certificate exists." machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Do not prompt for client certificate selection when no certificates or only one certificate exists.</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16789-0' platform='ie8' modified='2010-09-25'>
      <description>The "Include local directory path when uploading files to a server" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Include local directory path when uploading files to a server</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16714-8' platform='ie8' modified='2010-09-25'>
      <description>The "Access data sources across domains" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Access data sources across domains</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16851-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow font downloads" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow font downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16547-2' platform='ie8' modified='2010-09-25'>
      <description>The "XAML browser applications" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\XAML browser applications</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16094-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow drag and drop or copy and paste files" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow drag and drop or copy and paste files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16624-9' platform='ie8' modified='2010-09-25'>
      <description>The "Launching programs and unsafe files" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Launching programs and unsafe files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15198-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow drag and drop or copy and paste files" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow drag and drop or copy and paste files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15016-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow script-initiated windows without size or position constraints" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow script-initiated windows without size or position constraints</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16460-8' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for file downloads" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Automatic prompting for file downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16575-3' platform='ie8' modified='2010-09-25'>
      <description>The "Include local directory path when uploading files to a server" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Include local directory path when uploading files to a server</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16953-2' platform='ie8' modified='2010-09-25'>
      <description>The "Initialize and script ActiveX controls not marked as safe" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Initialize and script ActiveX controls not marked as safe</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16465-7' platform='ie8' modified='2010-09-25'>
      <description>The "XPS documents" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\XPS documents</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15920-2' platform='ie8' modified='2010-09-25'>
      <description>The "Submit non-encrypted form data" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Submit non-encrypted form data</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16861-7' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components signed with Authenticode" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Run .NET Framework-reliant components signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16872-4' platform='ie8' modified='2010-09-25'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Web sites in less privileged Web content zones can navigate into this zone</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16362-6' platform='ie8' modified='2010-09-25'>
      <description>The "Use Pop-up Blocker" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Use Pop-up Blocker</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16880-7' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components signed with Authenticode" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Run .NET Framework-reliant components signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15794-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow META REFRESH" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow META REFRESH</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16552-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow Scriptlets" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow Scriptlets</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16987-0' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Protected Mode" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Turn on Protected Mode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15900-4' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for ActiveX controls" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Automatic prompting for ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15594-5' platform='ie8' modified='2010-09-25'>
      <description>The "Do not prompt for client certificate selection when no certificates or only one certificate exists." machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Do not prompt for client certificate selection when no certificates or only one certificate exists.</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16549-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to prompt for information using scripted windows" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow websites to prompt for information using scripted windows</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16020-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to open windows without address or status bars" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow websites to open windows without address or status bars</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15021-9' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components not signed with Authenticode" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Run .NET Framework-reliant components not signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16375-8' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components not signed with Authenticode" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Run .NET Framework-reliant components not signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16238-8' platform='ie8' modified='2010-09-25'>
      <description>The "Software channel permissions" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Software channel permissions</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16613-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to prompt for information using scripted windows" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow websites to prompt for information using scripted windows</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15689-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow script-initiated windows without size or position constraints" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow script-initiated windows without size or position constraints</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16298-2' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for file downloads" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Automatic prompting for file downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15850-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow font downloads" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Allow font downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16382-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow scripting of Internet Explorer web browser control" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15904-6' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components signed with Authenticode" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Run .NET Framework-reliant components signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16030-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow drag and drop or copy and paste files" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow drag and drop or copy and paste files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16839-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to open windows without address or status bars" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow websites to open windows without address or status bars</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16242-0' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components not signed with Authenticode" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Run .NET Framework-reliant components not signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16976-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Protected Mode" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Turn on Protected Mode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16212-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn Off First-Run Opt-In" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Turn Off First-Run Opt-In</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15697-6' platform='ie8' modified='2010-09-25'>
      <description>The "Submit non-encrypted form data" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Submit non-encrypted form data</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14982-3' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for file downloads" machine setting should be configured correctly for the Locked-Down Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone\Automatic prompting for file downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16867-4' platform='ie8' modified='2010-09-25'>
      <description>The "Include local directory path when uploading files to a server" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Include local directory path when uploading files to a server</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16965-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow drag and drop or copy and paste files" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow drag and drop or copy and paste files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16193-5' platform='ie8' modified='2010-09-25'>
      <description>The "Scripting of Java applets" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Scripting of Java applets</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16416-0' platform='ie8' modified='2010-09-25'>
      <description>The "Submit non-encrypted form data" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Submit non-encrypted form data</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15980-6' platform='ie8' modified='2010-09-25'>
      <description>The "Run ActiveX controls and plugins" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Run ActiveX controls and plugins</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16013-5' platform='ie8' modified='2010-09-25'>
      <description>The "Launching programs and unsafe files" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Launching programs and unsafe files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15681-0' platform='ie8' modified='2010-09-25'>
      <description>The "Access data sources across domains" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Access data sources across domains</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16498-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow cut, copy or paste operations from the clipboard via script" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Allow cut, copy or paste operations from the clipboard via script</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16811-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow scripting of Internet Explorer web browser control" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16387-3' platform='ie8' modified='2010-09-25'>
      <description>The "Navigate windows and frames across different domains" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Navigate windows and frames across different domains</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16622-3' platform='ie8' modified='2010-09-25'>
      <description>The "Logon options" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Logon options</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16605-8' platform='ie8' modified='2010-09-25'>
      <description>The "Only allow approved domains to use ActiveX controls without prompt" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Only allow approved domains to use ActiveX controls without prompt</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17036-5' platform='ie8' modified='2010-09-25'>
      <description>The "Access data sources across domains" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Access data sources across domains</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16948-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow script-initiated windows without size or position constraints" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow script-initiated windows without size or position constraints</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16798-1' platform='ie8' modified='2010-09-25'>
      <description>The "Open files based on content, not file extension" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Open files based on content, not file extension</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16951-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow file downloads" machine setting should be configured correctly for the Locked-Down Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone\Allow file downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16540-7' platform='ie8' modified='2010-09-25'>
      <description>The "Only allow approved domains to use ActiveX controls without prompt" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Only allow approved domains to use ActiveX controls without prompt</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15674-5' platform='ie8' modified='2010-09-25'>
      <description>The "Run ActiveX controls and plugins" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Run ActiveX controls and plugins</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16504-3' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components signed with Authenticode" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Run .NET Framework-reliant components signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16885-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow script-initiated windows without size or position constraints" machine setting should be configured correctly for the Locked-Down Restricted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone\Allow script-initiated windows without size or position constraints</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16627-2' platform='ie8' modified='2010-09-25'>
      <description>The "Launching applications and files in an IFRAME" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Launching applications and files in an IFRAME</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16380-8' platform='ie8' modified='2010-09-25'>
      <description>The "Do not prompt for client certificate selection when no certificates or only one certificate exists." machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Do not prompt for client certificate selection when no certificates or only one certificate exists.</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16288-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn Off First-Run Opt-In" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Turn Off First-Run Opt-In</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16342-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow scripting of Internet Explorer web browser control" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15985-5' platform='ie8' modified='2010-09-25'>
      <description>The "Run ActiveX controls and plugins" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Run ActiveX controls and plugins</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16513-4' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for file downloads" machine setting should be configured correctly for the Locked-Down Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone\Automatic prompting for file downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16183-6' platform='ie8' modified='2010-09-25'>
      <description>The "Loose XAML files" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Loose XAML files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16010-1' platform='ie8' modified='2010-09-25'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" machine setting should be configured correctly for the Locked-Down Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone\Web sites in less privileged Web content zones can navigate into this zone</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16524-1' platform='ie8' modified='2010-09-25'>
      <description>The "File size limits for Local Machine zone" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Persistence Behavior\File size limits for Local Machine zone</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Persistence\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15903-8' platform='ie8' modified='2010-09-25'>
      <description>The "File size limits for Intranet zone" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Persistence Behavior\File size limits for Intranet zone</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Persistence\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16555-5' platform='ie8' modified='2010-09-25'>
      <description>The "File size limits for Internet zone" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Persistence Behavior\File size limits for Internet zone</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Persistence\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16317-0' platform='ie8' modified='2010-09-25'>
      <description>The "File size limits for Restricted Sites zone" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Persistence Behavior\File size limits for Restricted Sites zone</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Persistence\4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15776-8' platform='ie8' modified='2010-09-25'>
      <description>The "File size limits for Trusted Sites zone" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Persistence Behavior\File size limits for Trusted Sites zone</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Persistence\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15841-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to prompt for information using scripted windows" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow websites to prompt for information using scripted windows</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15360-1' platform='ie8' modified='2010-09-25'>
      <description>The "Run ActiveX controls and plugins" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Run ActiveX controls and plugins</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15705-7' platform='ie8' modified='2010-09-25'>
      <description>The "XAML browser applications" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\XAML browser applications</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15619-0' platform='ie8' modified='2010-09-25'>
      <description>The "Use SmartScreen Filter" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Use SmartScreen Filter</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15295-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow cut, copy or paste operations from the clipboard via script" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow cut, copy or paste operations from the clipboard via script</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14928-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active content over restricted protocols to access my computer" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow active content over restricted protocols to access my computer</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15818-8' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Cross-Site Scripting (XSS) Filter" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Turn on Cross-Site Scripting (XSS) Filter</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15802-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow binary and script behaviors" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow binary and script behaviors</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15762-8' platform='ie8' modified='2010-09-25'>
      <description>The "Turn Off First-Run Opt-In" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Turn Off First-Run Opt-In</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15168-8' platform='ie8' modified='2010-09-25'>
      <description>The "Download unsigned ActiveX controls" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Download unsigned ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14930-2' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components signed with Authenticode" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Run .NET Framework-reliant components signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15775-0' platform='ie8' modified='2010-09-25'>
      <description>The "Include local directory path when uploading files to a server" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Include local directory path when uploading files to a server</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15082-1' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Protected Mode" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Turn on Protected Mode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15534-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow scripting of Internet Explorer web browser control" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15771-9' platform='ie8' modified='2010-09-25'>
      <description>The "Scripting of Java applets" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Scripting of Java applets</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15714-9' platform='ie8' modified='2010-09-25'>
      <description>The "Launching applications and files in an IFRAME" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Launching applications and files in an IFRAME</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15219-9' platform='ie8' modified='2010-09-25'>
      <description>The "Access data sources across domains" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Access data sources across domains</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15866-7' platform='ie8' modified='2010-09-25'>
      <description>The "Display mixed content" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Display mixed content</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15908-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active scripting" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow active scripting</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15846-9' platform='ie8' modified='2010-09-25'>
      <description>The "Do not prompt for client certificate selection when no certificates or only one certificate exists." machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Do not prompt for client certificate selection when no certificates or only one certificate exists.</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15300-7' platform='ie8' modified='2010-09-25'>
      <description>The "Software channel permissions" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Software channel permissions</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15580-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow META REFRESH" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow META REFRESH</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15899-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow Scriptlets" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow Scriptlets</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15753-7' platform='ie8' modified='2010-09-25'>
      <description>The "Script ActiveX controls marked safe for scripting" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Script ActiveX controls marked safe for scripting</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15489-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow font downloads" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow font downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15234-8' platform='ie8' modified='2010-09-25'>
      <description>The "Submit non-encrypted form data" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Submit non-encrypted form data</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14934-4' platform='ie8' modified='2010-09-25'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Web sites in less privileged Web content zones can navigate into this zone</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14926-0' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for file downloads" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Automatic prompting for file downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15057-3' platform='ie8' modified='2010-09-25'>
      <description>The "Userdata persistence" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Userdata persistence</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14959-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow video and animation on a Web page that uses a legacy media player" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow video and animation on a Web page that uses a legacy media player</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15894-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow file downloads" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow file downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15621-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow installation of desktop items" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow installation of desktop items</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15286-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow drag and drop or copy and paste files" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow drag and drop or copy and paste files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15840-2' platform='ie8' modified='2010-09-25'>
      <description>The "Loose XAML files" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Loose XAML files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15476-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to open windows without address or status bars" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow websites to open windows without address or status bars</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15612-5' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components not signed with Authenticode" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Run .NET Framework-reliant components not signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15758-6' platform='ie8' modified='2010-09-25'>
      <description>The "Only allow approved domains to use ActiveX controls without prompt" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Only allow approved domains to use ActiveX controls without prompt</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15780-0' platform='ie8' modified='2010-09-25'>
      <description>The "Launching programs and unsafe files" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Launching programs and unsafe files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15084-7' platform='ie8' modified='2010-09-25'>
      <description>The "Logon options" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Logon options</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15784-2' platform='ie8' modified='2010-09-25'>
      <description>The "Initialize and script ActiveX controls not marked as safe" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Initialize and script ActiveX controls not marked as safe</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15767-7' platform='ie8' modified='2010-09-25'>
      <description>The "Use Pop-up Blocker" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Use Pop-up Blocker</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15736-2' platform='ie8' modified='2010-09-25'>
      <description>The "Open files based on content, not file extension" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Open files based on content, not file extension</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15814-7' platform='ie8' modified='2010-09-25'>
      <description>The "Navigate windows and frames across different domains" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Navigate windows and frames across different domains</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14943-5' platform='ie8' modified='2010-09-25'>
      <description>The "Disable .NET Framework Setup" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Disable .NET Framework Setup</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15824-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow script-initiated windows without size or position constraints" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow script-initiated windows without size or position constraints</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15793-3' platform='ie8' modified='2010-09-25'>
      <description>The "XPS documents" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\XPS documents</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15930-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow status bar updates via script" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow status bar updates via script</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15819-6' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for ActiveX controls" machine setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Automatic prompting for ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16551-4' platform='ie8' modified='2010-09-25'>
      <description>The "Add-on Management: Process List" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Add-on Management\Process List</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16269-3' platform='ie8' modified='2010-09-25'>
      <description>The "Add-on List" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Add-on Management\Add-on List</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Ext</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15982-2' platform='ie8' modified='2010-09-25'>
      <description>The "Deny all add-ons unless specifically allowed in the Add-on List" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Add-on Management\Deny all add-ons unless specifically allowed in the Add-on List</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Ext</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16921-9' platform='ie8' modified='2010-09-25'>
      <description>The "Add-on Management: All Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Add-on Management\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ADDON_MANAGEMENT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15886-5' platform='ie8' modified='2010-09-25'>
      <description>The "Scripted Window Security Restrictions: Process List" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Scripted Window Security Restrictions\Process List</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16462-4' platform='ie8' modified='2010-09-25'>
      <description>The "Scripted Window Security Restrictions: Internet Explorer Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Scripted Window Security Restrictions\Internet Explorer Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16467-3' platform='ie8' modified='2010-09-25'>
      <description>The "Scripted Window Security Restrictions: All Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Scripted Window Security Restrictions\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15804-8' platform='ie8' modified='2010-09-25'>
      <description>The "Use Policy List of Internet Explorer 7 sites" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Compatibility View\Use Policy List of Internet Explorer 7 sites</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation\PolicyList</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15822-0' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Compatibility View button" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Compatibility View\Turn off Compatibility View button</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\CommandBar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14932-8' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Internet Explorer 7 Standards Mode" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Compatibility View\Turn on Internet Explorer 7 Standards Mode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15575-4' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Internet Explorer Standards Mode for Local Intranet" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Compatibility View\Turn on Internet Explorer Standards Mode for Local Intranet</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15707-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Compatibility View" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Compatibility View\Turn off Compatibility View</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16656-1' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Data Execution Prevention" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Turn off Data Execution Prevention</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16661-1' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Data URI Support" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Turn off Data URI Support</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DATAURI</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15896-4' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Windows Search AutoComplete" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\AutoComplete\Turn off Windows Search AutoComplete</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\WindowsSearch</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15859-2' platform='ie8' modified='2010-09-25'>
      <description>The "Launching programs and unsafe files" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Launching programs and unsafe files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16385-7' platform='ie8' modified='2010-09-25'>
      <description>The "Download unsigned ActiveX controls" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Download unsigned ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16053-1' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components signed with Authenticode" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Run .NET Framework-reliant components signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15450-0' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for file downloads" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Automatic prompting for file downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16437-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow script-initiated windows without size or position constraints" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow script-initiated windows without size or position constraints</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15735-4' platform='ie8' modified='2010-09-25'>
      <description>The "Run ActiveX controls and plugins" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Run ActiveX controls and plugins</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16433-5' platform='ie8' modified='2010-09-25'>
      <description>The "Use SmartScreen Filter" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Use SmartScreen Filter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16424-4' platform='ie8' modified='2010-09-25'>
      <description>The "Software channel permissions" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Software channel permissions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16428-5' platform='ie8' modified='2010-09-25'>
      <description>The "Download signed ActiveX controls" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Download signed ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15460-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active content over restricted protocols to access my computer" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow active content over restricted protocols to access my computer</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16057-2' platform='ie8' modified='2010-09-25'>
      <description>The "Loose XAML files" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Loose XAML files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16398-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow META REFRESH" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow META REFRESH</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16328-7' platform='ie8' modified='2010-09-25'>
      <description>The "Navigate windows and frames across different domains" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Navigate windows and frames across different domains</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15673-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to open windows without address or status bars" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow websites to open windows without address or status bars</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16435-0' platform='ie8' modified='2010-09-25'>
      <description>The "Java permissions" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Java permissions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16397-2' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for ActiveX controls" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Automatic prompting for ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15913-7' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Cross-Site Scripting (XSS) Filter" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Turn on Cross-Site Scripting (XSS) Filter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15696-8' platform='ie8' modified='2010-09-25'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Web sites in less privileged Web content zones can navigate into this zone</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16248-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow drag and drop or copy and paste files" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow drag and drop or copy and paste files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16114-1' platform='ie8' modified='2010-09-25'>
      <description>The "Use Pop-up Blocker" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Use Pop-up Blocker</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16115-8' platform='ie8' modified='2010-09-25'>
      <description>The "Display mixed content" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Display mixed content</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16202-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow Scriptlets" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow Scriptlets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15421-1' platform='ie8' modified='2010-09-25'>
      <description>The "Initialize and script ActiveX controls not marked as safe" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Initialize and script ActiveX controls not marked as safe</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16330-3' platform='ie8' modified='2010-09-25'>
      <description>The "Launching applications and files in an IFRAME" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Launching applications and files in an IFRAME</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16411-1' platform='ie8' modified='2010-09-25'>
      <description>The "Scripting of Java applets" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Scripting of Java applets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15854-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow status bar updates via script" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow status bar updates via script</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15464-1' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Protected Mode" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Turn on Protected Mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16358-4' platform='ie8' modified='2010-09-25'>
      <description>The "Userdata persistence" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Userdata persistence</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15443-5' platform='ie8' modified='2010-09-25'>
      <description>The "Script ActiveX controls marked safe for scripting" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Script ActiveX controls marked safe for scripting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16216-4' platform='ie8' modified='2010-09-25'>
      <description>The "Include local directory path when uploading files to a server" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Include local directory path when uploading files to a server</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16103-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow video and animation on a Web page that uses a legacy media player" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow video and animation on a Web page that uses a legacy media player</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15640-6' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components not signed with Authenticode" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Run .NET Framework-reliant components not signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15827-9' platform='ie8' modified='2010-09-25'>
      <description>The "Open files based on content, not file extension" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Open files based on content, not file extension</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16119-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow font downloads" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow font downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15456-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow file downloads" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow file downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15868-3' platform='ie8' modified='2010-09-25'>
      <description>The "Submit non-encrypted form data" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Submit non-encrypted form data</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15823-8' platform='ie8' modified='2010-09-25'>
      <description>The "XPS documents" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\XPS documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15995-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow binary and script behaviors" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow binary and script behaviors</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16102-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to prompt for information using scripted windows" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow websites to prompt for information using scripted windows</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16422-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active scripting" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow active scripting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16431-9' platform='ie8' modified='2010-09-25'>
      <description>The "Access data sources across domains" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Access data sources across domains</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15447-6' platform='ie8' modified='2010-09-25'>
      <description>The "Only allow approved domains to use ActiveX controls without prompt" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Only allow approved domains to use ActiveX controls without prompt</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16261-0' platform='ie8' modified='2010-09-25'>
      <description>The "XAML browser applications" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\XAML browser applications</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16066-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn Off First-Run Opt-In" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Turn Off First-Run Opt-In</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15974-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow installation of desktop items" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow installation of desktop items</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16357-6' platform='ie8' modified='2010-09-25'>
      <description>The "Do not prompt for client certificate selection when no certificates or only one certificate exists." current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Do not prompt for client certificate selection when no certificates or only one certificate exists.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16379-0' platform='ie8' modified='2010-09-25'>
      <description>The "Logon options" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Logon options</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16132-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow scripting of Internet Explorer web browser control" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16264-4' platform='ie8' modified='2010-09-25'>
      <description>The "Disable .NET Framework Setup" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Disable .NET Framework Setup</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15591-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow cut, copy or paste operations from the clipboard via script" current user setting should be configured correctly for the Intranet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone\Allow cut, copy or paste operations from the clipboard via script</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16440-0' platform='ie8' modified='2010-09-25'>
      <description>The "Protection From Zone Elevation: Process List" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Protection From Zone Elevation\Process List</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16541-5' platform='ie8' modified='2010-09-25'>
      <description>The "Protection From Zone Elevation: All Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Protection From Zone Elevation\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16568-8' platform='ie8' modified='2010-09-25'>
      <description>The "Protection From Zone Elevation: Internet Explorer Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Protection From Zone Elevation\Internet Explorer Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15434-4' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent users from configuring background color" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Display settings\General Colors\Prevent users from configuring background color</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15685-1' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent the use of Windows colors" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Display settings\General Colors\Prevent the use of Windows colors</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15417-9' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent users from configuring text color" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Display settings\General Colors\Prevent users from configuring text color</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16931-8' platform='ie8' modified='2010-09-25'>
      <description>The "Local Machine Zone Restricted Protocols" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Network Protocol Lockdown\Restricted Protocols Per Security Zone\Local Machine Zone Restricted Protocols</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17080-3' platform='ie8' modified='2010-09-25'>
      <description>The "Intranet Zone Restricted Protocols" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Network Protocol Lockdown\Restricted Protocols Per Security Zone\Intranet Zone Restricted Protocols</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16944-1' platform='ie8' modified='2010-09-25'>
      <description>The "Internet Zone Restricted Protocols" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Network Protocol Lockdown\Restricted Protocols Per Security Zone\Internet Zone Restricted Protocols</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16662-9' platform='ie8' modified='2010-09-25'>
      <description>The "Restricted Sites Zone Restricted Protocols" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Network Protocol Lockdown\Restricted Protocols Per Security Zone\Restricted Sites Zone Restricted Protocols</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16097-8' platform='ie8' modified='2010-09-25'>
      <description>The "Trusted Sites Zone Restricted Protocols" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Network Protocol Lockdown\Restricted Protocols Per Security Zone\Trusted Sites Zone Restricted Protocols</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16327-9' platform='ie8' modified='2010-09-25'>
      <description>The "Mime Sniffing Safety Feature: Process List" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Mime Sniffing Safety Feature\Process List</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16322-0' platform='ie8' modified='2010-09-25'>
      <description>The "Mime Sniffing Safety Feature: All Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Mime Sniffing Safety Feature\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_SNIFFING</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15785-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on script debugging" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Advanced settings\Browsing\Turn on script debugging</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15996-2' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off friendly http error messages" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Advanced settings\Browsing\Turn off friendly http error messages</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16754-4' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on the display of a notification about every script error" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Advanced settings\Browsing\Turn on the display of a notification about every script error</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16758-5' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off configuring underline links" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Advanced settings\Browsing\Turn off configuring underline links</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15779-2' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off smooth scrolling" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Advanced settings\Browsing\Turn off smooth scrolling</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16302-2' platform='ie8' modified='2010-09-25'>
      <description>The "Information Bar: All Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Information Bar\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16324-6' platform='ie8' modified='2010-09-25'>
      <description>The "Information Bar: Internet Explorer Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Information Bar\Internet Explorer Processes</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16421-0' platform='ie8' modified='2010-09-25'>
      <description>The "Information Bar: Process List" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Information Bar\Process List</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15507-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active content over restricted protocols to access my computer" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow active content over restricted protocols to access my computer</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15751-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to open windows without address or status bars" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow websites to open windows without address or status bars</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16145-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to prompt for information using scripted windows" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow websites to prompt for information using scripted windows</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15520-0' platform='ie8' modified='2010-09-25'>
      <description>The "Use SmartScreen Filter" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Use SmartScreen Filter</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15314-8' platform='ie8' modified='2010-09-25'>
      <description>The "Disable .NET Framework Setup" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Disable .NET Framework Setup</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16151-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow META REFRESH" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow META REFRESH</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16138-0' platform='ie8' modified='2010-09-25'>
      <description>The "XAML browser applications" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\XAML browser applications</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16150-5' platform='ie8' modified='2010-09-25'>
      <description>The "Scripting of Java applets" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Scripting of Java applets</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16006-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow video and animation on a Web page that uses a legacy media player" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow video and animation on a Web page that uses a legacy media player</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15277-7' platform='ie8' modified='2010-09-25'>
      <description>The "Do not prompt for client certificate selection when no certificates or only one certificate exists." machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Do not prompt for client certificate selection when no certificates or only one certificate exists.</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15292-6' platform='ie8' modified='2010-09-25'>
      <description>The "Run ActiveX controls and plugins" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Run ActiveX controls and plugins</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16141-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow file downloads" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow file downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15309-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow binary and script behaviors" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow binary and script behaviors</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15311-4' platform='ie8' modified='2010-09-25'>
      <description>The "Script ActiveX controls marked safe for scripting" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Script ActiveX controls marked safe for scripting</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15268-6' platform='ie8' modified='2010-09-25'>
      <description>The "Display mixed content" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Display mixed content</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15643-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow scripting of Internet Explorer web browser control" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15993-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active scripting" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Allow active scripting</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16143-0' platform='ie8' modified='2010-09-25'>
      <description>The "Submit non-encrypted form data" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Submit non-encrypted form data</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16123-2' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for ActiveX controls" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\Automatic prompting for ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15629-9' platform='ie8' modified='2010-09-25'>
      <description>The "XPS documents" machine setting should be configured correctly for the Internet Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone\XPS documents</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16260-2' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Data URI Support" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Turn off Data URI Support</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DATAURI</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16785-8' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Internet Explorer Standards Mode for Local Intranet" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Compatibility View\Turn on Internet Explorer Standards Mode for Local Intranet</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16666-0' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Compatibility View" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Compatibility View\Turn off Compatibility View</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16652-0' platform='ie8' modified='2010-09-25'>
      <description>The "Use Policy List of Internet Explorer 7 sites" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Compatibility View\Use Policy List of Internet Explorer 7 sites</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation\PolicyList</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16679-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Compatibility View button" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Compatibility View\Turn off Compatibility View button</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\CommandBar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16674-4' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Internet Explorer 7 Standards Mode" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Compatibility View\Turn on Internet Explorer 7 Standards Mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16022-6' platform='ie8' modified='2010-09-25'>
      <description>The "Include updated Web site lists from Microsoft" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Compatibility View\Include updated Web site lists from Microsoft</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15946-7' platform='ie8' modified='2010-09-25'>
      <description>The "Use UTF-8 for mailto links" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Use UTF-8 for mailto links</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Protocols\Mailto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16690-0' platform='ie8' modified='2010-09-25'>
      <description>The "Disable the Advanced page" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Disable the Advanced page</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15805-5' platform='ie8' modified='2010-09-25'>
      <description>The "Send internationalized domain names" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Send internationalized domain names</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15803-0' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent ignoring certificate errors" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Prevent ignoring certificate errors</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16703-1' platform='ie8' modified='2010-09-25'>
      <description>The "Disable the Content page" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Disable the Content page</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16604-1' platform='ie8' modified='2010-09-25'>
      <description>The "Disable the General page" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Disable the General page</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16554-8' platform='ie8' modified='2010-09-25'>
      <description>The "Disable the Privacy page" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Disable the Privacy page</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16694-2' platform='ie8' modified='2010-09-25'>
      <description>The "Disable the Connections page" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Disable the Connections page</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16599-3' platform='ie8' modified='2010-09-25'>
      <description>The "Disable the Programs page" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Disable the Programs page</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16461-6' platform='ie8' modified='2010-09-25'>
      <description>The "Disable the Security page" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Disable the Security page</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16034-1' platform='ie8' modified='2010-09-25'>
      <description>The "Only allow approved domains to use ActiveX controls without prompt" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Only allow approved domains to use ActiveX controls without prompt</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16147-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow drag and drop or copy and paste files" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow drag and drop or copy and paste files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15857-6' platform='ie8' modified='2010-09-25'>
      <description>The "Script ActiveX controls marked safe for scripting" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Script ActiveX controls marked safe for scripting</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15733-9' platform='ie8' modified='2010-09-25'>
      <description>The "Disable .NET Framework Setup" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Disable .NET Framework Setup</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15729-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow video and animation on a Web page that uses a legacy media player" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow video and animation on a Web page that uses a legacy media player</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16597-7' platform='ie8' modified='2010-09-25'>
      <description>The "XPS documents" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\XPS documents</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16681-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow script-initiated windows without size or position constraints" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow script-initiated windows without size or position constraints</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16016-8' platform='ie8' modified='2010-09-25'>
      <description>The "XAML browser applications" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\XAML browser applications</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16629-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to prompt for information using scripted windows" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow websites to prompt for information using scripted windows</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16707-2' platform='ie8' modified='2010-09-25'>
      <description>The "Initialize and script ActiveX controls not marked as safe" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Initialize and script ActiveX controls not marked as safe</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16702-3' platform='ie8' modified='2010-09-25'>
      <description>The "Download signed ActiveX controls" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Download signed ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16508-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow installation of desktop items" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow installation of desktop items</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16583-7' platform='ie8' modified='2010-09-25'>
      <description>The "Software channel permissions" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Software channel permissions</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16423-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow META REFRESH" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow META REFRESH</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15893-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow status bar updates via script" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow status bar updates via script</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16559-7' platform='ie8' modified='2010-09-25'>
      <description>The "Download unsigned ActiveX controls" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Download unsigned ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16658-7' platform='ie8' modified='2010-09-25'>
      <description>The "Launching applications and files in an IFRAME" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Launching applications and files in an IFRAME</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15770-1' platform='ie8' modified='2010-09-25'>
      <description>The "Userdata persistence" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Userdata persistence</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15709-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow file downloads" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow file downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15699-2' platform='ie8' modified='2010-09-25'>
      <description>The "Do not prompt for client certificate selection when no certificates or only one certificate exists." machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Do not prompt for client certificate selection when no certificates or only one certificate exists.</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15713-1' platform='ie8' modified='2010-09-25'>
      <description>The "Loose XAML files" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Loose XAML files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16319-6' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Protected Mode" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Turn on Protected Mode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15953-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn Off First-Run Opt-In" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Turn Off First-Run Opt-In</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15706-5' platform='ie8' modified='2010-09-25'>
      <description>The "Submit non-encrypted form data" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Submit non-encrypted form data</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16544-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow binary and script behaviors" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow binary and script behaviors</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16165-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow font downloads" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow font downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15967-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active content over restricted protocols to access my computer" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow active content over restricted protocols to access my computer</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16640-5' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for file downloads" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Automatic prompting for file downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15708-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to open windows without address or status bars" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow websites to open windows without address or status bars</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15716-4' platform='ie8' modified='2010-09-25'>
      <description>The "Use Pop-up Blocker" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Use Pop-up Blocker</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16633-0' platform='ie8' modified='2010-09-25'>
      <description>The "Display mixed content" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Display mixed content</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15721-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow Scriptlets" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow Scriptlets</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16628-0' platform='ie8' modified='2010-09-25'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Web sites in less privileged Web content zones can navigate into this zone</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16262-8' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components signed with Authenticode" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Run .NET Framework-reliant components signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16012-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active scripting" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow active scripting</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16451-7' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for ActiveX controls" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Automatic prompting for ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16257-8' platform='ie8' modified='2010-09-25'>
      <description>The "Scripting of Java applets" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Scripting of Java applets</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16579-5' platform='ie8' modified='2010-09-25'>
      <description>The "Include local directory path when uploading files to a server" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Include local directory path when uploading files to a server</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16163-8' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Cross-Site Scripting (XSS) Filter" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Turn on Cross-Site Scripting (XSS) Filter</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16514-2' platform='ie8' modified='2010-09-25'>
      <description>The "Launching programs and unsafe files" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Launching programs and unsafe files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16578-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow scripting of Internet Explorer web browser control" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16266-9' platform='ie8' modified='2010-09-25'>
      <description>The "Logon options" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Logon options</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16680-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow cut, copy or paste operations from the clipboard via script" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Allow cut, copy or paste operations from the clipboard via script</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16623-1' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components not signed with Authenticode" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Run .NET Framework-reliant components not signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16526-6' platform='ie8' modified='2010-09-25'>
      <description>The "Navigate windows and frames across different domains" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Navigate windows and frames across different domains</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16403-8' platform='ie8' modified='2010-09-25'>
      <description>The "Access data sources across domains" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Access data sources across domains</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16619-9' platform='ie8' modified='2010-09-25'>
      <description>The "Open files based on content, not file extension" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Open files based on content, not file extension</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16404-6' platform='ie8' modified='2010-09-25'>
      <description>The "Run ActiveX controls and plugins" machine setting should be configured correctly for the Local Machine Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone\Run ActiveX controls and plugins</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15795-8' platform='ie8' modified='2010-09-25'>
      <description>The "Binary Behavior Security Restriction: All Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Binary Behavior Security Restriction\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15914-5' platform='ie8' modified='2010-09-25'>
      <description>The "Binary Behavior Security Restriction: Process List" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Binary Behavior Security Restriction\Process List</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16443-4' platform='ie8' modified='2010-09-25'>
      <description>The "Admin-approved behaviors" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Binary Behavior Security Restriction\Admin-approved behaviors</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16192-7' platform='ie8' modified='2010-09-25'>
      <description>The "Binary Behavior Security Restriction: Internet Explorer Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Binary Behavior Security Restriction\Internet Explorer Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16256-0' platform='ie8' modified='2010-09-25'>
      <description>The "Turn Off First-Run Opt-In" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Turn Off First-Run Opt-In</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15428-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow installation of desktop items" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow installation of desktop items</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15688-5' platform='ie8' modified='2010-09-25'>
      <description>The "XAML browser applications" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\XAML browser applications</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16058-0' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components not signed with Authenticode" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Run .NET Framework-reliant components not signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16023-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow font downloads" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow font downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16231-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow script-initiated windows without size or position constraints" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow script-initiated windows without size or position constraints</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15962-4' platform='ie8' modified='2010-09-25'>
      <description>The "Script ActiveX controls marked safe for scripting" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Script ActiveX controls marked safe for scripting</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16137-2' platform='ie8' modified='2010-09-25'>
      <description>The "Initialize and script ActiveX controls not marked as safe" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Initialize and script ActiveX controls not marked as safe</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15943-4' platform='ie8' modified='2010-09-25'>
      <description>The "Only allow approved domains to use ActiveX controls without prompt" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Only allow approved domains to use ActiveX controls without prompt</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16185-1' platform='ie8' modified='2010-09-25'>
      <description>The "Navigate windows and frames across different domains" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Navigate windows and frames across different domains</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16235-4' platform='ie8' modified='2010-09-25'>
      <description>The "XPS documents" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\XPS documents</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15344-5' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Cross-Site Scripting (XSS) Filter" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Turn on Cross-Site Scripting (XSS) Filter</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15372-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow drag and drop or copy and paste files" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow drag and drop or copy and paste files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15958-2' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for file downloads" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Automatic prompting for file downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15371-8' platform='ie8' modified='2010-09-25'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Web sites in less privileged Web content zones can navigate into this zone</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16002-8' platform='ie8' modified='2010-09-25'>
      <description>The "Loose XAML files" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Loose XAML files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16186-9' platform='ie8' modified='2010-09-25'>
      <description>The "Userdata persistence" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Userdata persistence</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15573-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active content over restricted protocols to access my computer" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow active content over restricted protocols to access my computer</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15661-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active scripting" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow active scripting</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16282-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow video and animation on a Web page that uses a legacy media player" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow video and animation on a Web page that uses a legacy media player</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16133-1' platform='ie8' modified='2010-09-25'>
      <description>The "Download unsigned ActiveX controls" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Download unsigned ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16194-3' platform='ie8' modified='2010-09-25'>
      <description>The "Include local directory path when uploading files to a server" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Include local directory path when uploading files to a server</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15369-2' platform='ie8' modified='2010-09-25'>
      <description>The "Disable .NET Framework Setup" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Disable .NET Framework Setup</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16354-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to prompt for information using scripted windows" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow websites to prompt for information using scripted windows</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16007-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to open windows without address or status bars" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow websites to open windows without address or status bars</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15370-0' platform='ie8' modified='2010-09-25'>
      <description>The "Access data sources across domains" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Access data sources across domains</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15921-0' platform='ie8' modified='2010-09-25'>
      <description>The "Use Pop-up Blocker" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Use Pop-up Blocker</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15628-1' platform='ie8' modified='2010-09-25'>
      <description>The "Logon options" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Logon options</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15564-8' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for ActiveX controls" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Automatic prompting for ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15998-8' platform='ie8' modified='2010-09-25'>
      <description>The "Submit non-encrypted form data" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Submit non-encrypted form data</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16300-6' platform='ie8' modified='2010-09-25'>
      <description>The "Software channel permissions" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Software channel permissions</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15542-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow META REFRESH" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow META REFRESH</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16146-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow binary and script behaviors" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow binary and script behaviors</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16365-9' platform='ie8' modified='2010-09-25'>
      <description>The "Run ActiveX controls and plugins" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Run ActiveX controls and plugins</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16345-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow Scriptlets" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow Scriptlets</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15820-4' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Protected Mode" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Turn on Protected Mode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15635-6' platform='ie8' modified='2010-09-25'>
      <description>The "Display mixed content" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Display mixed content</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15348-6' platform='ie8' modified='2010-09-25'>
      <description>The "Use SmartScreen Filter" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Use SmartScreen Filter</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16278-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow file downloads" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow file downloads</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16098-6' platform='ie8' modified='2010-09-25'>
      <description>The "Launching applications and files in an IFRAME" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Launching applications and files in an IFRAME</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16348-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow status bar updates via script" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow status bar updates via script</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16304-8' platform='ie8' modified='2010-09-25'>
      <description>The "Download signed ActiveX controls" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Download signed ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16199-2' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components signed with Authenticode" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Run .NET Framework-reliant components signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15648-9' platform='ie8' modified='2010-09-25'>
      <description>The "Scripting of Java applets" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Scripting of Java applets</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16018-4' platform='ie8' modified='2010-09-25'>
      <description>The "Launching programs and unsafe files" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Launching programs and unsafe files</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16208-1' platform='ie8' modified='2010-09-25'>
      <description>The "Open files based on content, not file extension" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Open files based on content, not file extension</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15441-9' platform='ie8' modified='2010-09-25'>
      <description>The "Do not prompt for client certificate selection when no certificates or only one certificate exists." machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Do not prompt for client certificate selection when no certificates or only one certificate exists.</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15994-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow scripting of Internet Explorer web browser control" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16245-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow cut, copy or paste operations from the clipboard via script" machine setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow cut, copy or paste operations from the clipboard via script</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16072-1' platform='ie8' modified='2010-09-25'>
      <description>The "Use HTTP 1.1" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Use HTTP 1.1</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16254-5' platform='ie8' modified='2010-09-25'>
      <description>The "Do not save encrypted pages to disk" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Do not save encrypted pages to disk</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16142-2' platform='ie8' modified='2010-09-25'>
      <description>The "Do not allow resetting Internet Explorer settings" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Do not allow resetting Internet Explorer settings</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15878-2' platform='ie8' modified='2010-09-25'>
      <description>The "Empty Temporary Internet Files folder when browser is closed" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Empty Temporary Internet Files folder when browser is closed</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Cache</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16827-8' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off ClearType" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Turn off ClearType</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15872-5' platform='ie8' modified='2010-09-25'>
      <description>The "Play animations in web pages" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Play animations in web pages</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15877-4' platform='ie8' modified='2010-09-25'>
      <description>The "Use HTTP 1.1 through proxy connections" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Use HTTP 1.1 through proxy connections</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16241-2' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Caret Browsing support" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Turn on Caret Browsing support</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\CaretBrowsing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15863-4' platform='ie8' modified='2010-09-25'>
      <description>The "Play sounds in web pages" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Play sounds in web pages</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16027-5' platform='ie8' modified='2010-09-25'>
      <description>The "Intranet Zone Template" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone Template</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Intranet Settings\Template Policies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16805-4' platform='ie8' modified='2010-09-25'>
      <description>The "Local Machine Zone Template" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone Template</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Local Machine Zone Settings\Template Policies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15885-7' platform='ie8' modified='2010-09-25'>
      <description>The "Locked-Down Internet Zone Template" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone Template</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Lockdown Settings\Template Policies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15828-7' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on automatic detection of the intranet" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Turn on automatic detection of the intranet</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16439-2' platform='ie8' modified='2010-09-25'>
      <description>The "Trusted Sites Zone Template" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone Template</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Trusted Sites Settings\Template Policies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16644-7' platform='ie8' modified='2010-09-25'>
      <description>The "Locked-Down Intranet Zone Template" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone Template</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Intranet Lockdown Settings\Template Policies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16657-9' platform='ie8' modified='2010-09-25'>
      <description>The "Restricted Sites Zone Template" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone Template</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Restricted Sites Settings\Template Policies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16800-5' platform='ie8' modified='2010-09-25'>
      <description>The "Locked-Down Restricted Sites Zone Template" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone Template</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Restricted Sites Lockdown Settings\Template Policies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16255-2' platform='ie8' modified='2010-09-25'>
      <description>The "Locked-Down Local Machine Zone Template" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone Template</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Local Machine Zone Lockdown Settings\Template Policies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16458-2' platform='ie8' modified='2010-09-25'>
      <description>The "Locked-Down Trusted Sites Zone Template" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone Template</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Trusted Sites Lockdown Settings\Template Policies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16630-6' platform='ie8' modified='2010-09-25'>
      <description>The "Intranet Sites: Include all sites that bypass the proxy server" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Sites: Include all sites that bypass the proxy server</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15815-4' platform='ie8' modified='2010-09-25'>
      <description>The "Site to Zone Assignment List" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Site to Zone Assignment List</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16158-8' platform='ie8' modified='2010-09-25'>
      <description>The "Intranet Sites: Include all local (intranet) sites not listed in other zones" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Sites: Include all local (intranet) sites not listed in other zones</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15829-5' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Information bar notification for intranet content" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Turn on Information bar notification for intranet content</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16780-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Warn about Certificate Address Mismatch" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Turn on Warn about Certificate Address Mismatch</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16384-0' platform='ie8' modified='2010-09-25'>
      <description>The "Internet Zone Template" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone Template</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Template Policies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15660-4' platform='ie8' modified='2010-09-25'>
      <description>The "Pop-up allow list" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Pop-up allow list</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\New Windows</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16166-1' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off configuration of tabbed browsing pop-up behavior" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off configuration of tabbed browsing pop-up behavior</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\TabbedBrowsing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15789-1' platform='ie8' modified='2010-09-25'>
      <description>The "Configure new tab page default behavior" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Configure new tab page default behavior</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16005-1' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off the auto-complete feature for web addresses" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off the auto-complete feature for web addresses</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Explorer\AutoComplete</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16106-7' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off tabbed browsing" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off tabbed browsing</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\TabbedBrowsing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16349-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Compatibility Logging" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn on Compatibility Logging</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\Feature_Enable_Compat_logging</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15563-0' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off configuration of default behavior of new tab creation" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off configuration of default behavior of new tab creation</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\TabbedBrowsing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15749-5' platform='ie8' modified='2010-09-25'>
      <description>The "Set tab process growth" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Set tab process growth</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16353-5' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off displaying the Internet Explorer Help Menu" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off displaying the Internet Explorer Help Menu</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16388-1' platform='ie8' modified='2010-09-25'>
      <description>The "Restrict changing the default search provider" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Restrict changing the default search provider</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15397-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on menu bar by default" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn on menu bar by default</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16290-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off suggestions for all user-installed providers" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off suggestions for all user-installed providers</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\SearchScopes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15704-0' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Favorites bar" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off Favorites bar</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\LinksBar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15545-7' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off the activation of the quick pick menu" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off the activation of the quick pick menu</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\SearchScopes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15414-6' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Automatic Crash Recovery Prompt" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off Automatic Crash Recovery Prompt</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Recovery</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16191-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off configuration of window reuse" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off configuration of window reuse</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15419-5' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Quick Tabs functionality" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off Quick Tabs functionality</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\TabbedBrowsing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16271-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Managing Pop-up Allow list" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off Managing Pop-up Allow list</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15655-4' platform='ie8' modified='2010-09-25'>
      <description>The "Add a specific list of search providers to the user's search provider list" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Add a specific list of search providers to the user's search provider list</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15917-8' platform='ie8' modified='2010-09-25'>
      <description>The "Restrict search providers to a specific list of providers" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Restrict search providers to a specific list of providers</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16393-1' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off page zooming functionality" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off page zooming functionality</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\ZOOM</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16249-5' platform='ie8' modified='2010-09-25'>
      <description>The "Enforce Full Screen Mode" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Enforce Full Screen Mode</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15403-9' platform='ie8' modified='2010-09-25'>
      <description>The "Customize User Agent String" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Customize User Agent String</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15613-3' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent Internet Explorer Search box from displaying" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Prevent Internet Explorer Search box from displaying</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16378-2' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off managing Pop-up filter level" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off managing Pop-up filter level</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16060-6' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Reopen Last Browsing Session" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off Reopen Last Browsing Session</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Recovery</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16148-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off pop-up management" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Turn off pop-up management</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16309-7' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off picture display" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Advanced settings\Multimedia\Turn off picture display</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16573-8' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off automatic image resizing" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Advanced settings\Multimedia\Turn off automatic image resizing</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16569-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow the display of image download placeholders" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Advanced settings\Multimedia\Allow the display of image download placeholders</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16688-4' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off smart image dithering" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Advanced settings\Multimedia\Turn off smart image dithering</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14923-7' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off InPrivate Browsing" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\InPrivate\Turn off InPrivate Browsing</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Privacy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15465-8' platform='ie8' modified='2010-09-25'>
      <description>The "InPrivate Filtering Threshold" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\InPrivate\InPrivate Filtering Threshold</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Safety\PrivacIE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15725-5' platform='ie8' modified='2010-09-25'>
      <description>The "Do not collect InPrivate Filtering data" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\InPrivate\Do not collect InPrivate Filtering data</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Safety\PrivacIE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15855-0' platform='ie8' modified='2010-09-25'>
      <description>The "Disable toolbars and extensions when InPrivate Browsing starts" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\InPrivate\Disable toolbars and extensions when InPrivate Browsing starts</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Safety\PrivacIE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15337-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off InPrivate Filtering" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\InPrivate\Turn off InPrivate Filtering</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Safety\PrivacIE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16928-4' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off InPrivate Filtering" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\InPrivate\Turn off InPrivate Filtering</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Safety\PrivacIE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16810-4' platform='ie8' modified='2010-09-25'>
      <description>The "Disable toolbars and extensions when InPrivate Browsing starts" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\InPrivate\Disable toolbars and extensions when InPrivate Browsing starts</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Safety\PrivacIE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16171-1' platform='ie8' modified='2010-09-25'>
      <description>The "Do not collect InPrivate Filtering data" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\InPrivate\Do not collect InPrivate Filtering data</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Safety\PrivacIE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16164-6' platform='ie8' modified='2010-09-25'>
      <description>The "InPrivate Filtering Threshold" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\InPrivate\InPrivate Filtering Threshold</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Safety\PrivacIE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15910-3' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent users from choosing default text size" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Display settings\Prevent users from choosing default text size</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16286-7' platform='ie8' modified='2010-09-25'>
      <description>The "Download unsigned ActiveX controls" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Download unsigned ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16693-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow Scriptlets" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow Scriptlets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16802-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to prompt for information using scripted windows" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow websites to prompt for information using scripted windows</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16701-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow binary and script behaviors" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow binary and script behaviors</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16493-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Protected Mode" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Turn on Protected Mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16815-3' platform='ie8' modified='2010-09-25'>
      <description>The "Logon options" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Logon options</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16723-9' platform='ie8' modified='2010-09-25'>
      <description>The "Disable .NET Framework Setup" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Disable .NET Framework Setup</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16520-9' platform='ie8' modified='2010-09-25'>
      <description>The "Use Pop-up Blocker" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Use Pop-up Blocker</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16313-9' platform='ie8' modified='2010-09-25'>
      <description>The "Do not prompt for client certificate selection when no certificates or only one certificate exists." current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Do not prompt for client certificate selection when no certificates or only one certificate exists.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16621-5' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for file downloads" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Automatic prompting for file downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16586-0' platform='ie8' modified='2010-09-25'>
      <description>The "Allow drag and drop or copy and paste files" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow drag and drop or copy and paste files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16308-9' platform='ie8' modified='2010-09-25'>
      <description>The "Allow installation of desktop items" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow installation of desktop items</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16731-2' platform='ie8' modified='2010-09-25'>
      <description>The "XPS documents" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\XPS documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16157-0' platform='ie8' modified='2010-09-25'>
      <description>The "Download signed ActiveX controls" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Download signed ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16506-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow websites to open windows without address or status bars" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow websites to open windows without address or status bars</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15852-7' platform='ie8' modified='2010-09-25'>
      <description>The "Loose XAML files" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Loose XAML files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16647-0' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Cross-Site Scripting (XSS) Filter" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Turn on Cross-Site Scripting (XSS) Filter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16368-3' platform='ie8' modified='2010-09-25'>
      <description>The "Allow META REFRESH" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow META REFRESH</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16048-1' platform='ie8' modified='2010-09-25'>
      <description>The "Submit non-encrypted form data" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Submit non-encrypted form data</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15833-7' platform='ie8' modified='2010-09-25'>
      <description>The "Run ActiveX controls and plugins" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Run ActiveX controls and plugins</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16207-3' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components signed with Authenticode" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Run .NET Framework-reliant components signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16634-8' platform='ie8' modified='2010-09-25'>
      <description>The "Userdata persistence" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Userdata persistence</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16509-2' platform='ie8' modified='2010-09-25'>
      <description>The "XAML browser applications" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\XAML browser applications</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16747-8' platform='ie8' modified='2010-09-25'>
      <description>The "Automatic prompting for ActiveX controls" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Automatic prompting for ActiveX controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15845-1' platform='ie8' modified='2010-09-25'>
      <description>The "Web sites in less privileged Web content zones can navigate into this zone" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Web sites in less privileged Web content zones can navigate into this zone</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15837-8' platform='ie8' modified='2010-09-25'>
      <description>The "Allow font downloads" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow font downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16289-1' platform='ie8' modified='2010-09-25'>
      <description>The "Allow file downloads" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow file downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16008-5' platform='ie8' modified='2010-09-25'>
      <description>The "Access data sources across domains" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Access data sources across domains</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16639-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow script-initiated windows without size or position constraints" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow script-initiated windows without size or position constraints</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16355-0' platform='ie8' modified='2010-09-25'>
      <description>The "Turn Off First-Run Opt-In" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Turn Off First-Run Opt-In</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16766-8' platform='ie8' modified='2010-09-25'>
      <description>The "Initialize and script ActiveX controls not marked as safe" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Initialize and script ActiveX controls not marked as safe</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16564-7' platform='ie8' modified='2010-09-25'>
      <description>The "Software channel permissions" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Software channel permissions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16791-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow video and animation on a Web page that uses a legacy media player" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow video and animation on a Web page that uses a legacy media player</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16771-8' platform='ie8' modified='2010-09-25'>
      <description>The "Navigate windows and frames across different domains" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Navigate windows and frames across different domains</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16084-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow cut, copy or paste operations from the clipboard via script" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow cut, copy or paste operations from the clipboard via script</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15835-2' platform='ie8' modified='2010-09-25'>
      <description>The "Scripting of Java applets" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Scripting of Java applets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16686-8' platform='ie8' modified='2010-09-25'>
      <description>The "Only allow approved domains to use ActiveX controls without prompt" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Only allow approved domains to use ActiveX controls without prompt</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16021-8' platform='ie8' modified='2010-09-25'>
      <description>The "Open files based on content, not file extension" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Open files based on content, not file extension</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16806-2' platform='ie8' modified='2010-09-25'>
      <description>The "Allow status bar updates via script" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow status bar updates via script</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16170-3' platform='ie8' modified='2010-09-25'>
      <description>The "Launching applications and files in an IFRAME" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Launching applications and files in an IFRAME</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16612-4' platform='ie8' modified='2010-09-25'>
      <description>The "Use SmartScreen Filter" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Use SmartScreen Filter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16038-2' platform='ie8' modified='2010-09-25'>
      <description>The "Run .NET Framework-reliant components not signed with Authenticode" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Run .NET Framework-reliant components not signed with Authenticode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15848-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active content over restricted protocols to access my computer" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow active content over restricted protocols to access my computer</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16277-6' platform='ie8' modified='2010-09-25'>
      <description>The "Allow scripting of Internet Explorer web browser control" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow scripting of Internet Explorer web browser control</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16377-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active scripting" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Allow active scripting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16625-6' platform='ie8' modified='2010-09-25'>
      <description>The "Display mixed content" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Display mixed content</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16409-5' platform='ie8' modified='2010-09-25'>
      <description>The "Include local directory path when uploading files to a server" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Include local directory path when uploading files to a server</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15965-7' platform='ie8' modified='2010-09-25'>
      <description>The "Script ActiveX controls marked safe for scripting" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Script ActiveX controls marked safe for scripting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16250-3' platform='ie8' modified='2010-09-25'>
      <description>The "Java permissions" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Java permissions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16167-9' platform='ie8' modified='2010-09-25'>
      <description>The "Launching programs and unsafe files" current user setting should be configured correctly for the Trusted Sites Zone.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone\Launching programs and unsafe files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15849-3' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent the configuration of cipher strength update information URLs" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Component Updates\Help Menu &gt; About Internet Explorer\Prevent the configuration of cipher strength update information URLs</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15964-0' platform='ie8' modified='2010-09-25'>
      <description>The "Enable cut, copy or paste operations from the clipboard if URLACTION_SCRIPT_PASTE is set to Prompt: Internet Explorer Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Application Compatibility\Enable cut, copy or paste operations from the clipboard if URLACTION_SCRIPT_PASTE is set to Prompt\Internet Explorer Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\Feature_Enable_Script_Paste_URLAction_If_Prompt</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15991-3' platform='ie8' modified='2010-09-25'>
      <description>The "Enable cut, copy or paste operations from the clipboard if URLACTION_SCRIPT_PASTE is set to Prompt: Process List" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Application Compatibility\Enable cut, copy or paste operations from the clipboard if URLACTION_SCRIPT_PASTE is set to Prompt\Process List</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15969-9' platform='ie8' modified='2010-09-25'>
      <description>The "Enable cut, copy or paste operations from the clipboard if URLACTION_SCRIPT_PASTE is set to Prompt: All Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Application Compatibility\Enable cut, copy or paste operations from the clipboard if URLACTION_SCRIPT_PASTE is set to Prompt\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\Feature_Enable_Script_Paste_URLAction_If_Prompt</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16956-5' platform='ie8' modified='2010-09-25'>
      <description>The "Hide the Command Bar" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Toolbars\Hide the Command Bar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\CommandBar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16722-1' platform='ie8' modified='2010-09-25'>
      <description>The "Disable customizing browser toolbar buttons" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Toolbars\Disable customizing browser toolbar buttons</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16952-4' platform='ie8' modified='2010-09-25'>
      <description>The "Auto-hide the Toolbars" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Toolbars\Auto-hide the Toolbars</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\CommandBar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16051-5' platform='ie8' modified='2010-09-25'>
      <description>The "Customize Command Labels" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Toolbars\Customize Command Labels</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\CommandBar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16930-0' platform='ie8' modified='2010-09-25'>
      <description>The "Set location of Stop and Refresh buttons" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Toolbars\Set location of Stop and Refresh buttons</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\CommandBar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16700-7' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Developer Tools" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Toolbars\Turn off Developer Tools</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\IEDevTools</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16863-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off toolbar upgrade tool" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Toolbars\Turn off toolbar upgrade tool</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16727-0' platform='ie8' modified='2010-09-25'>
      <description>The "Lock all Toolbars" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Toolbars\Lock all Toolbars</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Toolbar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16969-8' platform='ie8' modified='2010-09-25'>
      <description>The "Use large Icons for Command Buttons" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Toolbars\Use large Icons for Command Buttons</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\CommandBar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16590-2' platform='ie8' modified='2010-09-25'>
      <description>The "Disable customizing browser toolbars" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Toolbars\Disable customizing browser toolbars</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16868-2' platform='ie8' modified='2010-09-25'>
      <description>The "Hide the Status Bar" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Toolbars\Hide the Status Bar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15060-7' platform='ie8' modified='2010-09-25'>
      <description>The "Network Protocol Lockdown: All Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Network Protocol Lockdown\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15791-7' platform='ie8' modified='2010-09-25'>
      <description>The "Network Protocol Lockdown: Internet Explorer Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Network Protocol Lockdown\Internet Explorer Processes</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15817-0' platform='ie8' modified='2010-09-25'>
      <description>The "Network Protocol Lockdown: Process List" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Network Protocol Lockdown\Process List</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15296-7' platform='ie8' modified='2010-09-25'>
      <description>The "Intranet Zone Restricted Protocols" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Network Protocol Lockdown\Restricted Protocols Per Security Zone\Intranet Zone Restricted Protocols</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15529-1' platform='ie8' modified='2010-09-25'>
      <description>The "Trusted Sites Zone Restricted Protocols" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Network Protocol Lockdown\Restricted Protocols Per Security Zone\Trusted Sites Zone Restricted Protocols</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15040-9' platform='ie8' modified='2010-09-25'>
      <description>The "Restricted Sites Zone Restricted Protocols" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Network Protocol Lockdown\Restricted Protocols Per Security Zone\Restricted Sites Zone Restricted Protocols</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15890-7' platform='ie8' modified='2010-09-25'>
      <description>The "Local Machine Zone Restricted Protocols" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Network Protocol Lockdown\Restricted Protocols Per Security Zone\Local Machine Zone Restricted Protocols</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15895-6' platform='ie8' modified='2010-09-25'>
      <description>The "Internet Zone Restricted Protocols" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Network Protocol Lockdown\Restricted Protocols Per Security Zone\Internet Zone Restricted Protocols</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\RestrictedProtocols</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16175-2' platform='ie8' modified='2010-09-25'>
      <description>The "Local Machine Zone Lockdown Security: Process List" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Local Machine Zone Lockdown Security\Process List</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16669-4' platform='ie8' modified='2010-09-25'>
      <description>The "Local Machine Zone Lockdown Security: Internet Explorer Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Local Machine Zone Lockdown Security\Internet Explorer Processes</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16162-0' platform='ie8' modified='2010-09-25'>
      <description>The "Local Machine Zone Lockdown Security: All Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Local Machine Zone Lockdown Security\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16061-4' platform='ie8' modified='2010-09-25'>
      <description>The "MK Protocol Security Restriction: Process List" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\MK Protocol Security Restriction\Process List</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16982-1' platform='ie8' modified='2010-09-25'>
      <description>The "MK Protocol Security Restriction: All Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\MK Protocol Security Restriction\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16938-3' platform='ie8' modified='2010-09-25'>
      <description>The "MK Protocol Security Restriction: Internet Explorer Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\MK Protocol Security Restriction\Internet Explorer Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16128-1' platform='ie8' modified='2010-09-25'>
      <description>The "Information Bar: Internet Explorer Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Information Bar\Internet Explorer Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15726-3' platform='ie8' modified='2010-09-25'>
      <description>The "Information Bar: All Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Information Bar\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITYBAND</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15264-5' platform='ie8' modified='2010-09-25'>
      <description>The "Information Bar: Process List" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Information Bar\Process List</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17109-0' platform='ie8' modified='2010-09-25'>
      <description>The "Maximum number of connections per server (HTTP 1.0)" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\AJAX\Maximum number of connections per server (HTTP 1.0)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16161-2' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Cross Document Messaging" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\AJAX\Turn off Cross Document Messaging</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CROSS_DOCUMENT_MESSAGING</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16743-7' platform='ie8' modified='2010-09-25'>
      <description>The "Maximum number of connections per server (HTTP 1.1)" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\AJAX\Maximum number of connections per server (HTTP 1.1)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17122-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off the XDomainRequest Object" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\AJAX\Turn off the XDomainRequest Object</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XDOMAINREQUEST</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17113-2' platform='ie8' modified='2010-09-25'>
      <description>The "Enable Native XMLHttpRequest Support" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\AJAX\Enable Native XMLHttpRequest Support</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15717-2' platform='ie8' modified='2010-09-25'>
      <description>The "Auto-hide the Toolbars" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Toolbars\Auto-hide the Toolbars</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\CommandBar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15950-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Developer Tools" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Toolbars\Turn off Developer Tools</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\IEDevTools</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15972-3' platform='ie8' modified='2010-09-25'>
      <description>The "Lock all Toolbars" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Toolbars\Lock all Toolbars</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Toolbar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15474-0' platform='ie8' modified='2010-09-25'>
      <description>The "Use large Icons for Command Buttons" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Toolbars\Use large Icons for Command Buttons</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\CommandBar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15945-9' platform='ie8' modified='2010-09-25'>
      <description>The "Set location of Stop and Refresh buttons" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Toolbars\Set location of Stop and Refresh buttons</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\CommandBar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15472-4' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off toolbar upgrade tool" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Toolbars\Turn off toolbar upgrade tool</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15874-1' platform='ie8' modified='2010-09-25'>
      <description>The "Hide the Command Bar" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Toolbars\Hide the Command Bar</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\CommandBar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15471-6' platform='ie8' modified='2010-09-25'>
      <description>The "Customize Command Labels" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Toolbars\Customize Command Labels</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\CommandBar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15860-0' platform='ie8' modified='2010-09-25'>
      <description>The "Hide the Status Bar" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Toolbars\Hide the Status Bar</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16394-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off the XDomainRequest Object" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\AJAX\Turn off the XDomainRequest Object</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_XDOMAINREQUEST</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16244-6' platform='ie8' modified='2010-09-25'>
      <description>The "Maximum number of connections per server (HTTP 1.1)" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\AJAX\Maximum number of connections per server (HTTP 1.1)</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPERSERVER</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16275-0' platform='ie8' modified='2010-09-25'>
      <description>The "Maximum number of connections per server (HTTP 1.0)" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\AJAX\Maximum number of connections per server (HTTP 1.0)</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MAXCONNECTIONSPER1_0SERVER</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16372-5' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Cross Document Messaging" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\AJAX\Turn off Cross Document Messaging</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_CROSS_DOCUMENT_MESSAGING</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15496-3' platform='ie8' modified='2010-09-25'>
      <description>The "Enable Native XMLHttpRequest Support" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\AJAX\Enable Native XMLHttpRequest Support</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16472-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Windows Search AutoComplete" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\AutoComplete\Turn off Windows Search AutoComplete</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\WindowsSearch</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16704-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on inline AutoComplete for Web addresses" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\AutoComplete\Turn on inline AutoComplete for Web addresses</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Explorer\AutoComplete</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15484-9' platform='ie8' modified='2010-09-25'>
      <description>The "Consistent Mime Handling: All Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Consistent Mime Handling\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15836-0' platform='ie8' modified='2010-09-25'>
      <description>The "Consistent Mime Handling: Internet Explorer Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Consistent Mime Handling\Internet Explorer Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16087-9' platform='ie8' modified='2010-09-25'>
      <description>The "Consistent Mime Handling: Process List" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Consistent Mime Handling\Process List</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16405-3' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent Deleting Temporary Internet Files" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Delete Browsing History\Prevent Deleting Temporary Internet Files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Privacy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16414-5' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent Deleting Favorites Site Data" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Delete Browsing History\Prevent Deleting Favorites Site Data</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Privacy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15670-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off "Delete Browsing History" functionality" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Delete Browsing History\Turn off "Delete Browsing History" functionality</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16427-7' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent Deleting Form Data" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Delete Browsing History\Prevent Deleting Form Data</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15683-6' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent Deleting Passwords" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Delete Browsing History\Prevent Deleting Passwords</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16432-7' platform='ie8' modified='2010-09-25'>
      <description>The "Disable "Configuring History"" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Delete Browsing History\Disable "Configuring History"</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15533-3' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent Deleting Web sites that the User has Visited" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Delete Browsing History\Prevent Deleting Web sites that the User has Visited</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Privacy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15466-6' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent Deleting Cookies" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Delete Browsing History\Prevent Deleting Cookies</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Privacy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15925-1' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent Deleting InPrivate Filtering data" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Delete Browsing History\Prevent Deleting InPrivate Filtering data</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Privacy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16332-9' platform='ie8' modified='2010-09-25'>
      <description>The "Restrict File Download: All Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Restrict File Download\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16337-8' platform='ie8' modified='2010-09-25'>
      <description>The "Restrict File Download: Internet Explorer Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Restrict File Download\Internet Explorer Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16323-8' platform='ie8' modified='2010-09-25'>
      <description>The "Restrict File Download: Process List" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Restrict File Download\Process List</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16293-3' platform='ie8' modified='2010-09-25'>
      <description>The "Local Machine Zone Lockdown Security: Process List" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Local Machine Zone Lockdown Security\Process List</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16672-8' platform='ie8' modified='2010-09-25'>
      <description>The "Local Machine Zone Lockdown Security: Internet Explorer Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Local Machine Zone Lockdown Security\Internet Explorer Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15799-0' platform='ie8' modified='2010-09-25'>
      <description>The "Local Machine Zone Lockdown Security: All Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Local Machine Zone Lockdown Security\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16518-3' platform='ie8' modified='2010-09-25'>
      <description>The "Protection From Zone Elevation: Process List" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Protection From Zone Elevation\Process List</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16641-3' platform='ie8' modified='2010-09-25'>
      <description>The "Protection From Zone Elevation: All Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Protection From Zone Elevation\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ZONE_ELEVATION</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16862-5' platform='ie8' modified='2010-09-25'>
      <description>The "Disable the Programs page" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Disable the Programs page</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16858-3' platform='ie8' modified='2010-09-25'>
      <description>The "Disable the Content page" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Disable the Content page</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16981-3' platform='ie8' modified='2010-09-25'>
      <description>The "Use UTF-8 for mailto links" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Use UTF-8 for mailto links</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Protocols\Mailto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16488-9' platform='ie8' modified='2010-09-25'>
      <description>The "Disable the General page" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Disable the General page</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16990-4' platform='ie8' modified='2010-09-25'>
      <description>The "Send internationalized domain names" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Send internationalized domain names</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16598-5' platform='ie8' modified='2010-09-25'>
      <description>The "Disable the Connections page" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Disable the Connections page</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16068-9' platform='ie8' modified='2010-09-25'>
      <description>The "Disable the Privacy page" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Disable the Privacy page</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16112-5' platform='ie8' modified='2010-09-25'>
      <description>The "Binary Behavior Security Restriction: All Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Binary Behavior Security Restriction\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16389-9' platform='ie8' modified='2010-09-25'>
      <description>The "Admin-approved behaviors" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Binary Behavior Security Restriction\Admin-approved behaviors</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15631-5' platform='ie8' modified='2010-09-25'>
      <description>The "Binary Behavior Security Restriction: Process List" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Binary Behavior Security Restriction\Process List</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16376-6' platform='ie8' modified='2010-09-25'>
      <description>The "Binary Behavior Security Restriction: Internet Explorer Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Binary Behavior Security Restriction\Internet Explorer Processes</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BEHAVIORS</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15410-4' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Automatic Signup" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Advanced settings\Signup Settings\Turn on Automatic Signup</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\IEAK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15951-7' platform='ie8' modified='2010-09-25'>
      <description>The "Microsoft Chat" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Administrator Approved Controls\Microsoft Chat</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\AllowedControls</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16101-8' platform='ie8' modified='2010-09-25'>
      <description>The "Microsoft Agent" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Administrator Approved Controls\Microsoft Agent</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\AllowedControls</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15867-5' platform='ie8' modified='2010-09-25'>
      <description>The "Shockwave Flash" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Administrator Approved Controls\Shockwave Flash</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\AllowedControls</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15937-6' platform='ie8' modified='2010-09-25'>
      <description>The "Carpoint" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Administrator Approved Controls\Carpoint</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\AllowedControls</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15616-6' platform='ie8' modified='2010-09-25'>
      <description>The "Audio/Video Player" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Administrator Approved Controls\Audio/Video Player</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\AllowedControls</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15224-9' platform='ie8' modified='2010-09-25'>
      <description>The "MSNBC" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Administrator Approved Controls\MSNBC</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\AllowedControls</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15140-7' platform='ie8' modified='2010-09-25'>
      <description>The "Investor" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Administrator Approved Controls\Investor</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\AllowedControls</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16000-2' platform='ie8' modified='2010-09-25'>
      <description>The "Microsoft Survey Control" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Administrator Approved Controls\Microsoft Survey Control</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\AllowedControls</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16074-7' platform='ie8' modified='2010-09-25'>
      <description>The "Microsoft Scriptlet Component" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Administrator Approved Controls\Microsoft Scriptlet Component</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\AllowedControls</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16070-5' platform='ie8' modified='2010-09-25'>
      <description>The "NetShow File Transfer Control" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Administrator Approved Controls\NetShow File Transfer Control</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\AllowedControls</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15378-3' platform='ie8' modified='2010-09-25'>
      <description>The "DHTML Edit Control" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Administrator Approved Controls\DHTML Edit Control</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\AllowedControls</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15978-0' platform='ie8' modified='2010-09-25'>
      <description>The "Menu Controls" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Administrator Approved Controls\Menu Controls</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\AllowedControls</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16037-4' platform='ie8' modified='2010-09-25'>
      <description>The "Disable Open in New Window menu option" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Browser menus\Disable Open in New Window menu option</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15786-7' platform='ie8' modified='2010-09-25'>
      <description>The "Disable Context menu" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Browser menus\Disable Context menu</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15933-5' platform='ie8' modified='2010-09-25'>
      <description>The "File menu: Disable New menu option" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Browser menus\File menu: Disable New menu option</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15131-6' platform='ie8' modified='2010-09-25'>
      <description>The "Help menu: Remove 'Tour' menu option" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Browser menus\Help menu: Remove 'Tour' menu option</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15929-3' platform='ie8' modified='2010-09-25'>
      <description>The "Help menu: Remove 'Send Feedback' menu option" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Browser menus\Help menu: Remove 'Send Feedback' menu option</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15905-3' platform='ie8' modified='2010-09-25'>
      <description>The "File menu: Disable Save As Web Page Complete" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Browser menus\File menu: Disable Save As Web Page Complete</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Infodelivery\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15955-8' platform='ie8' modified='2010-09-25'>
      <description>The "File menu: Disable Open menu option" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Browser menus\File menu: Disable Open menu option</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15808-9' platform='ie8' modified='2010-09-25'>
      <description>The "View menu: Disable Source menu option" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Browser menus\View menu: Disable Source menu option</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15125-8' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Print Menu" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Browser menus\Turn off Print Menu</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16042-4' platform='ie8' modified='2010-09-25'>
      <description>The "File menu: Disable closing the browser and Explorer windows" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Browser menus\File menu: Disable closing the browser and Explorer windows</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15302-3' platform='ie8' modified='2010-09-25'>
      <description>The "File menu: Disable Save As... menu option" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Browser menus\File menu: Disable Save As... menu option</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15918-6' platform='ie8' modified='2010-09-25'>
      <description>The "View menu: Disable Full Screen menu option" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Browser menus\View menu: Disable Full Screen menu option</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15927-7' platform='ie8' modified='2010-09-25'>
      <description>The "Tools menu: Disable Internet Options... menu option" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Browser menus\Tools menu: Disable Internet Options... menu option</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16052-3' platform='ie8' modified='2010-09-25'>
      <description>The "Hide Favorites menu" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Browser menus\Hide Favorites menu</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15923-6' platform='ie8' modified='2010-09-25'>
      <description>The "Scripted Window Security Restrictions: Process List" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Scripted Window Security Restrictions\Process List</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15928-5' platform='ie8' modified='2010-09-25'>
      <description>The "Scripted Window Security Restrictions: All Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Scripted Window Security Restrictions\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WINDOW_RESTRICTIONS</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-17005-0' platform='ie8' modified='2010-09-25'>
      <description>The "MK Protocol Security Restriction: Process List" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\MK Protocol Security Restriction\Process List</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16763-5' platform='ie8' modified='2010-09-25'>
      <description>The "MK Protocol Security Restriction: All Processes" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\MK Protocol Security Restriction\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_MK_PROTOCOL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15341-1' platform='ie8' modified='2010-09-25'>
      <description>The "Object Caching Protection: Internet Explorer Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Object Caching Protection\Internet Explorer Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16214-9' platform='ie8' modified='2010-09-25'>
      <description>The "Object Caching Protection: All Processes" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Object Caching Protection\All Processes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_OBJECT_CACHING</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15844-4' platform='ie8' modified='2010-09-25'>
      <description>The "Object Caching Protection: Process List" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Security Features\Object Caching Protection\Process List</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15637-2' platform='ie8' modified='2010-09-25'>
      <description>The "Restricted Sites Zone Template" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Restricted Sites Zone Template</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Restricted Sites Settings\Template Policies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15316-3' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Warn about Certificate Address Mismatch" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Turn on Warn about Certificate Address Mismatch</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16301-4' platform='ie8' modified='2010-09-25'>
      <description>The "Intranet Sites: Include all sites that bypass the proxy server" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Sites: Include all sites that bypass the proxy server</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16172-9' platform='ie8' modified='2010-09-25'>
      <description>The "Locked-Down Internet Zone Template" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Internet Zone Template</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Lockdown Settings\Template Policies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15887-3' platform='ie8' modified='2010-09-25'>
      <description>The "Trusted Sites Zone Template" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Trusted Sites Zone Template</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Trusted Sites Settings\Template Policies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16111-7' platform='ie8' modified='2010-09-25'>
      <description>The "Intranet Zone Template" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Zone Template</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Intranet Settings\Template Policies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16297-4' platform='ie8' modified='2010-09-25'>
      <description>The "Locked-Down Local Machine Zone Template" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Local Machine Zone Template</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Local Machine Zone Lockdown Settings\Template Policies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15865-9' platform='ie8' modified='2010-09-25'>
      <description>The "Internet Zone Template" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Internet Zone Template</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Template Policies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16259-4' platform='ie8' modified='2010-09-25'>
      <description>The "Site to Zone Assignment List" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Site to Zone Assignment List</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16273-5' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Information bar notification for intranet content" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Turn on Information bar notification for intranet content</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16306-3' platform='ie8' modified='2010-09-25'>
      <description>The "Locked-Down Intranet Zone Template" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Intranet Zone Template</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Intranet Lockdown Settings\Template Policies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16124-0' platform='ie8' modified='2010-09-25'>
      <description>The "Local Machine Zone Template" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Local Machine Zone Template</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Local Machine Zone Settings\Template Policies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16284-2' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on automatic detection of the intranet" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Turn on automatic detection of the intranet</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16287-5' platform='ie8' modified='2010-09-25'>
      <description>The "Locked-Down Restricted Sites Zone Template" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Restricted Sites Zone Template</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Restricted Sites Lockdown Settings\Template Policies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16310-5' platform='ie8' modified='2010-09-25'>
      <description>The "Locked-Down Trusted Sites Zone Template" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Locked-Down Trusted Sites Zone Template</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Trusted Sites Lockdown Settings\Template Policies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16120-8' platform='ie8' modified='2010-09-25'>
      <description>The "Intranet Sites: Include all local (intranet) sites not listed in other zones" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Sites: Include all local (intranet) sites not listed in other zones</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16049-9' platform='ie8' modified='2010-09-25'>
      <description>The "Intranet Sites: Include all network paths (UNCs)" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Security Page\Intranet Sites: Include all network paths (UNCs)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16801-3' platform='ie8' modified='2010-09-25'>
      <description>The "Play sounds in web pages" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Play sounds in web pages</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15924-4' platform='ie8' modified='2010-09-25'>
      <description>The "Allow active content from CDs to run on user machines" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Allow active content from CDs to run on user machines</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16056-4' platform='ie8' modified='2010-09-25'>
      <description>The "Check for signatures on downloaded programs" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Check for signatures on downloaded programs</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Download</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15932-7' platform='ie8' modified='2010-09-25'>
      <description>The "Allow software to run or install even if the signature is invalid" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Allow software to run or install even if the signature is invalid</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Download</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15938-4' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off Encryption Support" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Turn off Encryption Support</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15940-0' platform='ie8' modified='2010-09-25'>
      <description>The "Empty Temporary Internet Files folder when browser is closed" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Empty Temporary Internet Files folder when browser is closed</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Cache</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16908-6' platform='ie8' modified='2010-09-25'>
      <description>The "Do not allow resetting Internet Explorer settings" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Do not allow resetting Internet Explorer settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16899-7' platform='ie8' modified='2010-09-25'>
      <description>The "Automatically check for Internet Explorer updates" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Automatically check for Internet Explorer updates</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16592-8' platform='ie8' modified='2010-09-25'>
      <description>The "Check for server certificate revocation" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Check for server certificate revocation</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16920-1' platform='ie8' modified='2010-09-25'>
      <description>The "Play animations in web pages" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Play animations in web pages</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16725-4' platform='ie8' modified='2010-09-25'>
      <description>The "Turn off ClearType" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Turn off ClearType</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16742-9' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on Caret Browsing support" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Turn on Caret Browsing support</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\CaretBrowsing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16606-6' platform='ie8' modified='2010-09-25'>
      <description>The "Use HTTP 1.1 through proxy connections" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Use HTTP 1.1 through proxy connections</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15973-1' platform='ie8' modified='2010-09-25'>
      <description>The "Do not save encrypted pages to disk" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Do not save encrypted pages to disk</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16720-5' platform='ie8' modified='2010-09-25'>
      <description>The "Allow third-party browser extensions" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Allow third-party browser extensions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16916-9' platform='ie8' modified='2010-09-25'>
      <description>The "Use HTTP 1.1" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Control Panel\Advanced Page\Use HTTP 1.1</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16383-2' platform='ie8' modified='2010-09-25'>
      <description>The "Turn on the hover color option" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Display settings\Link Colors\Turn on the hover color option</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16515-9' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent users from configuring the color of links that have already been clicked" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Display settings\Link Colors\Prevent users from configuring the color of links that have already been clicked</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-16770-0' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent users from configuring the hover color" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Display settings\Link Colors\Prevent users from configuring the hover color</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-15911-1' platform='ie8' modified='2010-09-25'>
      <description>The "Prevent users from configuring the color of links that have not yet been clicked" current user setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Windows Components\Internet Explorer\Internet Settings\Display settings\Link Colors\Prevent users from configuring the color of links that have not yet been clicked</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Internet Explorer 8
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19747-5' platform='iis5' modified='2013-02-11'>
      <description>The path of the IIS Web Root folder should be configured correctly.</description>
      <parameters>
        <parameter>(1) local path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1)  Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 1 Internet Information Services Installation
The Default Install Directory pg 12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19709-5' platform='iis5' modified='2013-02-11'>
      <description>The IIS Web Root directory should be named appropriately.</description>
      <parameters>
        <parameter>(1) directory name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the desired website &gt; Properties &gt; Home Directory tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 1 Internet Information Services Installation
The Default Install Directory pg 12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19914-1' platform='iis5' modified='2013-02-11'>
      <description>Individual IP addresses should be configured as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) IP address</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Server &gt; Web Site Identification &gt; IP address</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://support.microsoft.com/kb/323972</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19994-3' platform='iis5' modified='2013-02-11'>
      <description>The specified websites should be configured to use the appropriate network interfaces.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Server &gt; Web Site Identification &gt; All Unassigned</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 3 Services Installation and Administration
World Wide Web (WWW) Services pg 39</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19736-8' platform='iis5' modified='2013-02-11'>
      <description>The master home directory "Enable Logging" setting should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Server &gt; Enable Logging</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 2 Internet Services Manager – Master Properties
Master Properties
WWW Service pg 23-24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19368-0' platform='iis5' modified='2013-02-11'>
      <description>The master home directory "Read" permission should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Home Directory tab &gt; Read</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 2 Internet Services Manager – Master Properties
Master Properties
WWW Service pg 23-24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19642-8' platform='iis5' modified='2013-02-11'>
      <description>The master home directory "Write" permission should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Home Directory tab &gt; Write</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 2 Internet Services Manager – Master Properties
Master Properties
WWW Service pg 23-24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19739-2' platform='iis5' modified='2013-02-11'>
      <description>The master home directory "Script Source Access" permission should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Home Directory tab &gt; Script Source</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 2 Internet Services Manager – Master Properties
Master Properties
WWW Service pg 23-24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19996-8' platform='iis5' modified='2013-02-11'>
      <description>The master home directory "Directory Browsing" permission should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Home Directory tab &gt; Directory Browsing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 2 Internet Services Manager – Master Properties
Master Properties
WWW Service pg 23-24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19252-6' platform='iis5' modified='2013-02-11'>
      <description>The master home directory "Log Visits" permission should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Home Directory tab &gt; Log Visits</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 2 Internet Services Manager – Master Properties
Master Properties
WWW Service pg 23-24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19993-5' platform='iis5' modified='2013-02-11'>
      <description>The master home directory "Index this resource" permission should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) none/scripts/scripts&amp;executables</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Home Directory tab &gt; Index this resource</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 2 Internet Services Manager – Master Properties
Master Properties
WWW Service pg 23-24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19726-9' platform='iis5' modified='2013-02-11'>
      <description>The master home directory "Execute Permissions" permission should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Home Directory tab &gt; Execute Permissions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 2 Internet Services Manager – Master Properties
Master Properties
WWW Service pg 23-24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19728-5' platform='iis5' modified='2013-02-11'>
      <description>The master home directory "Anonymous Access" permission for IIS websites should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Directory Security &gt; Authentication and Access Control tab &gt; Anonymous Access</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 2 Internet Services Manager – Master Properties
Master Properties
WWW Service pg 24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19795-4' platform='iis5' modified='2013-02-11'>
      <description>The master home directory "Basic Authentication" setting should be enabled or disabled.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Directory Security &gt; Authentication and Access Control tab &gt; Authenticated Access</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 2 Internet Services Manager – Master Properties
Master Properties
WWW Service pg 24</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19973-7' platform='iis5' modified='2013-02-11'>
      <description>The master home directory "Integrated Windows Authentication" setting should be enabled or disabled.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Directory Security &gt; Authentication and Access Control tab &gt; Authenticated Access</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 2 Internet Services Manager – Master Properties
Master Properties
WWW Service pg 25</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19952-1' platform='iis5' modified='2013-02-11'>
      <description>The "Enable Logging" setting should be enabled or disabled for the specified web server</description>
      <parameters>
        <parameter>(1) TARGET: server</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Server &gt; Enable Logging</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 3 Services Installation and Administration
Summary of Web Server Configuration Issues pg 39</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19921-6' platform='iis5' modified='2013-02-11'>
      <description>The "Read" permission should be enabled or disabled as appropriate for the home directory of the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Read</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 3 Services Installation and Administration
World Wide Web (WWW) Services pg 41-42</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19724-4' platform='iis5' modified='2013-02-11'>
      <description>The "Write" privilege  should be enabled or disabled as appropriate for the home directory of the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Write</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 3 Services Installation and Administration
World Wide Web (WWW) Services pg 41-42</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19920-8' platform='iis5' modified='2013-02-11'>
      <description>The "Script Source Access" permission should be enabled or disabled as appropriate for the home directory of the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Home Directory tab &gt; Script Source</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 3 Services Installation and Administration
World Wide Web (WWW) Services pg 41-42</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20027-9' platform='iis5' modified='2013-02-11'>
      <description>The "Directory Browsing" permission should be enabled or disabled as appropriate for the home directory of the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Directory Browsing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 3 Services Installation and Administration
World Wide Web (WWW) Services pg 41-42</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19889-5' platform='iis5' modified='2013-02-11'>
      <description>The"Log Visits" permission should be enabled or disabled as appropriate for the home directory of the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Log Visits</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 3 Services Installation and Administration
World Wide Web (WWW) Services pg 41-42</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19701-2' platform='iis5' modified='2013-02-11'>
      <description>The  "Index this resource" permission should be enabled or disabled as appropriate for the home directory of the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Index this resource</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://technet.microsoft.com/en-us/library/bb742408.aspx</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19841-6' platform='iis5' modified='2013-02-11'>
      <description>The "Execute Permissions" permission should be set correctly for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) none/scripts/scripts&amp;executables</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Execute Permissions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 3 Services Installation and Administration
World Wide Web (WWW) Services pg 42</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19900-0' platform='iis5' modified='2013-02-11'>
      <description>The  "Anonymous Access" permission should be enabled or disabled as appropriate for the home directory of the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Directory Security &gt; Authentication and Access Control tab &gt; Anonymous Access</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 3 Services Installation and Administration
World Wide Web (WWW) Services pg 46</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19570-1' platform='iis5' modified='2013-02-11'>
      <description>Basic Authentication should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Directory Security &gt; Authentication and Access Control tab &gt; Authenticated Access</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 2 Internet Services Manager – Master Properties
Master Properties
WWW Service pg 23</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19474-6' platform='iis5' modified='2013-02-11'>
      <description>Integrated Windows Authentication should be enabled or disabled as appropriate the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Directory Security &gt; Authentication and Access Control tab &gt; Authenticated Access</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 2 Internet Services Manager – Master Properties
Master Properties
WWW Service pg 23</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19851-5' platform='iis5' modified='2013-02-11'>
      <description>The WWW service Special Characters In Shells setting should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\AllowSpecialCharsInShell</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://msdn.microsoft.com/ja-jp/library/aa711451.aspx</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19906-7' platform='iis5' modified='2013-02-11'>
      <description>IIS WWW service SSL error logging should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\Schannel\EventLogging</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://support.microsoft.com/kb/260729</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19604-8' platform='iis5' modified='2013-02-11'>
      <description>The RDSServer.DataFactory object should be enable or disabeld as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\ADCLaunch\RDSServer.Factory</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://technet.microsoft.com/en-us/security/bulletin/fq99-025</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19568-5' platform='iis5' modified='2013-02-11'>
      <description>The AdvancedDataFactory object should be enable or disabeld as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\ADCLaunch\AdvancedDataFactory</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://technet.microsoft.com/en-us/security/bulletin/fq99-025</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19441-5' platform='iis5' modified='2013-02-11'>
      <description>The VbBusObj.VbBusObjCls object should be enable or disabeld as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\ADCLaunch\VbBusObj.VbBusObjCls</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://technet.microsoft.com/en-us/security/bulletin/fq99-025</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19584-2' platform='iis5' modified='2013-02-11'>
      <description>The '.printer' extension mapping should be configured as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Configuration button &gt; App Mappings tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Script Mappings pg 76</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20007-1' platform='iis5' modified='2013-02-11'>
      <description>The '.htw' extension mapping should be configured as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Configuration button &gt; App Mappings tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Script Mappings pg 76</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19051-2' platform='iis5' modified='2013-02-11'>
      <description>The '.ida' extension mapping should be configured as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Configuration button &gt; App Mappings tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Script Mappings pg 76</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19075-1' platform='iis5' modified='2013-02-11'>
      <description>The '.idq' extension mapping should be configured as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Configuration button &gt; App Mappings tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Script Mappings pg 76</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20047-7' platform='iis5' modified='2013-02-11'>
      <description>The '.idc' extension mapping should be configured as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Configuration button &gt; App Mappings tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Script Mappings pg 76</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19367-2' platform='iis5' modified='2013-02-11'>
      <description>The '.shtm' extension mapping should be configured as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Configuration button &gt; App Mappings tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Script Mappings pg 76</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19760-8' platform='iis5' modified='2013-02-11'>
      <description>The '.stm' extension mapping should be configured as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Configuration button &gt; App Mappings tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Script Mappings pg 76</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19668-3' platform='iis5' modified='2013-02-11'>
      <description>The '.shtml' extension mapping should be configured as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Configuration button &gt; App Mappings tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Script Mappings pg 76</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19992-7' platform='iis5' modified='2013-02-11'>
      <description>Relative path traversal should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: webiste</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Configuration button &gt; Enable Parent Paths</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 3 Services Installation and Administration
World Wide Web (WWW) Services pg 43</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19918-2' platform='iis5' modified='2013-02-11'>
      <description>The startup type of the IIS Admin (IISAdmin) service should be correct.</description>
      <parameters>
        <parameter>(1) automatic/manual/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the Services Administrative Tool </technical_mechanism>
        <technical_mechanism>(2) definied by Group Policy</technical_mechanism>
        <technical_mechanism>(3) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IISADMIN\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 1 Internet Information Services Installation
IIS Services pg 15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19586-7' platform='iis5' modified='2013-02-11'>
      <description>Permissions on the \Inetpub directory should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 1 Internet Information Services Installation
IIS Services pg 15</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19957-0' platform='iis5' modified='2013-02-11'>
      <description>Permissions on the %SystemDirectory%\inetsrv directory should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 1 Internet Information Services Installation
The Default Install Directory pg 11</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19834-1' platform='iis5' modified='2013-02-11'>
      <description>Permissions on  %SystemDirectory%\inetsrv\asp.dll should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 1 Internet Information Services Installation
The Default Install Directory
Table 1 Permission Settings pg 12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19743-4' platform='iis5' modified='2013-02-11'>
      <description>Permissions on the Web Root "Images" directory should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 1 Internet Information Services Installation
The Default Install Directory
Table 1 Permission Settings pg 12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19874-7' platform='iis5' modified='2013-02-11'>
      <description>Permissions on the Web Root "scripts" directory should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 1 Internet Information Services Installation
The Default Install Directory
Table 1 Permission Settings pg 12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19812-7' platform='iis5' modified='2013-02-11'>
      <description>Permissions on the Web Root "executables" directory should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 1 Internet Information Services Installation
The Default Install Directory
Table 1 Permission Settings pg 12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19693-1' platform='iis5' modified='2013-02-11'>
      <description>Permissions on the Web Root "docs" directory should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 1 Internet Information Services Installation
The Default Install Directory
Table 1 Permission Settings pg 12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19953-9' platform='iis5' modified='2013-02-11'>
      <description>Permissions on the Web Root "home" directory should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 1 Internet Information Services Installation
The Default Install Directory
Table 1 Permission Settings pg 12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19755-8' platform='iis5' modified='2013-02-11'>
      <description>Permissions on the Web Root "include" directory should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 1 Internet Information Services Installation
The Default Install Directory
Table 1 Permission Settings pg 12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19925-7' platform='iis5' modified='2013-02-11'>
      <description>Permissions on the Web Root directory should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 1 Internet Information Services Installation
The Default Install Directory
Table 1 Permission Settings pg 12</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19849-9' platform='iis5' modified='2013-02-11'>
      <description>Permissions on the default Logfiles directory should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Auditing pg 70</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19870-5' platform='iis5' modified='2013-02-11'>
      <description>The file auditing for the directory \%SystemRoot%\System32\Inetsrv should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) events to  audit (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's SACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Auditing pg 70</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19777-2' platform='iis5' modified='2013-02-11'>
      <description>The file auditing for the Inetpub directory should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) events to  audit (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's SACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Auditing pg 70</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19247-6' platform='iis5' modified='2013-02-11'>
      <description>The file auditing for the directory Web Root should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) events to  audit (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's SACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Auditing pg 70</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19757-4' platform='iis5' modified='2013-02-11'>
      <description>HTTP protocol logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Auditing pg 72</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19767-3' platform='iis5' modified='2013-02-11'>
      <description>Date logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Auditing pg 72</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19355-7' platform='iis5' modified='2013-02-11'>
      <description>Time logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Auditing pg 72</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19508-1' platform='iis5' modified='2013-02-11'>
      <description>Client IP Address logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Auditing pg 72</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19483-7' platform='iis5' modified='2013-02-11'>
      <description>User name logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Auditing pg 72</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19052-0' platform='iis5' modified='2013-02-11'>
      <description>User agent logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Auditing pg 72</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19905-9' platform='iis5' modified='2013-02-11'>
      <description>Method logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Auditing pg 72</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20030-3' platform='iis5' modified='2013-02-11'>
      <description>URI stem logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Auditing pg 72</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19700-4' platform='iis5' modified='2013-02-11'>
      <description>URL query logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Auditing pg 72</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19931-5' platform='iis5' modified='2013-02-11'>
      <description>Server IP address logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Auditing pg 72</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19694-9' platform='iis5' modified='2013-02-11'>
      <description>Server port logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Auditing pg 72</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19393-8' platform='iis5' modified='2013-02-11'>
      <description>Protocol status logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Auditing pg 72</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19502-4' platform='iis5' modified='2013-02-11'>
      <description>Win32 status logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Auditing pg 72</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19979-4' platform='iis5' modified='2013-02-11'>
      <description>The path of the HTTP Log folder  should be configured correctly for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) local path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Auditing pg 72</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19540-4' platform='iis5' modified='2013-02-11'>
      <description>The file auditing for the Metaback directory should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) events to  audit (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's SACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://support.microsoft.com/kb/271071</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20031-1' platform='iis5' modified='2013-02-11'>
      <description>The membership of the IUSR account should be configured correctly.</description>
      <parameters>
        <parameter>(1) set of accounts</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by Local or Group Policy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 1 Internet Information Services Installation
Post Installation pg 10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19758-2' platform='iis5' modified='2013-02-11'>
      <description>The IUSR account should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by Local or Group Policy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 1 Internet Information Services Installation
Post Installation pg 9</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19378-9' platform='iis5' modified='2013-02-11'>
      <description>The Default IWAM account should be configured correctly.</description>
      <parameters>
        <parameter>(1) valid name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by Local or Group Policy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 1 Internet Information Services Installation
Post Installation pg 10</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19794-7' platform='iis5' modified='2013-02-11'>
      <description>The size of the IIS client request buffer should should be set correctly.</description>
      <parameters>
        <parameter>(1) number of bytes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\MaxClientRequestBuffer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://technet.microsoft.com/en-us/library/bb878118.aspx</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19644-4' platform='iis5' modified='2013-02-11'>
      <description>Server Side Includes should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>'SSIExecDisable' key in IIS metabase file</technical_mechanism>
        <technical_mechanism>(2) cscript adsutil.vbs set w3svc/.../SSIExecDisable</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://support.microsoft.com/kb/195291</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19630-3' platform='iis5' modified='2013-02-11'>
      <description>Web-based password reset IIS application mappings (.htr) should be configured correctly.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Service manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Configuration button &gt;App Mappings tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services
Script Mappings pg 75</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19434-0' platform='iis5' modified='2013-02-11'>
      <description>The required permissions for the registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC should be assigned.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://support.microsoft.com/kb/271071</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19810-1' platform='iis5' modified='2013-02-11'>
      <description>IIS Application Protection should be set correctly.</description>
      <parameters>
        <parameter>(1) low, medium, high</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Application Protection</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 3 Services Installation and Administration
World Wide Web (WWW) Services pg 43</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19951-3' platform='iis5' modified='2013-02-11'>
      <description>The required auditing for the file Metabase.bin should be enabled.</description>
      <parameters>
        <parameter>(1) set of accounts (2) events to  audit (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's SACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 1 Internet Information Services Installation
Securing the Metabase pg 16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19599-0' platform='iis5' modified='2013-02-11'>
      <description>IIS Sample files should be installed or not as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism> files in \Inetpub\iissamples</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services 
IIS Default Samples and Printers pg 78</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20039-4' platform='iis5' modified='2013-02-11'>
      <description>The sample Data Access files should be installed or not as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) files in \Program Files\Common Files\System\msadc\Samples</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services 
IIS Default Samples and Printers pg 78</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19830-9' platform='iis5' modified='2013-02-11'>
      <description>IIS Help files should be installed or not as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) files in %SystemRoot%\help\iishelp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services 
IIS Default Samples and Printers pg 78</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19985-1' platform='iis5' modified='2013-02-11'>
      <description>Remote Account password changes should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1)  files in %SystemRoot%\System32\Inetsrv\iisadmpwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services 
IIS Default Samples and Printers pg 78</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19651-9' platform='iis5' modified='2013-02-11'>
      <description>IIS sample Web Printing files should be installed or not as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism> files in %SystemRoot%\web\printers</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Guide to the Secure Configuration and Administration of Microsoft Internet Information Services 5.0'>Chapter 4 Additional Security Services 
IIS Default Samples and Printers pg 78</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19815-0' platform='iis6' modified='2013-02-11'>
      <description>The path of the IIS Web Root folder should be configured correctly.</description>
      <parameters>
        <parameter>(1) local path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1)  Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The web document (home) directory must be on a separate partition from the web servers system files.
STIG ID: WG205 IIS6  Rule ID: SV-30041r2_rule  Vuln ID: V-3333</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19592-5' platform='iis6' modified='2013-02-11'>
      <description>The IIS Web Root directory should be named appropriately.</description>
      <parameters>
        <parameter>(1) directory names</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Cert-In Securing IIS 6.0 Web Server'>4.2.6 Securing the Web Site Directory and Content, pg 21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19534-7' platform='iis6' modified='2013-02-11'>
      <description>Individual IP addresses should be configured as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) IP address</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Server &gt; Web Site Identification &gt; IP address</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/1c1d212b-18ae-414a-b5ec-eaf5b000a0c3.mspx?mfr=true</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19871-3' platform='iis6' modified='2013-02-11'>
      <description>The specified websites should be configured to use the appropriate network interfaces.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Server &gt; Web Site Identification &gt; All Unassigned</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/1c1d212b-18ae-414a-b5ec-eaf5b000a0c3.mspx?mfr=true</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19689-9' platform='iis6' modified='2013-02-11'>
      <description>The master home directory "Enable Logging" setting should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Server &gt; Enable Logging</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://technet.microsoft.com/en-us/library/cc779359%28v=ws.10%29.aspx</reference>
        <reference resource_id='Cert-In Securing IIS 6.0 Web Server'>Table 6: Web Site Permissions That Are Supported by IIS 6.0 pg 21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19133-8' platform='iis6' modified='2013-02-11'>
      <description>The master home directory "Read" permission should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Home Directory tab &gt; Read</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Cert-In Securing IIS 6.0 Web Server'>Table 6: Web Site Permissions That Are Supported by IIS 6.0 pg 21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20048-5' platform='iis6' modified='2013-02-11'>
      <description>The master home directory "Write" permission should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Home Directory tab &gt; Write</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Cert-In Securing IIS 6.0 Web Server'>Table 6: Web Site Permissions That Are Supported by IIS 6.0 pg 21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20017-0' platform='iis6' modified='2013-02-11'>
      <description>The master home directory "Script Source Access" permission should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Home Directory tab &gt; Script Source</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Cert-In Securing IIS 6.0 Web Server'>Table 6: Web Site Permissions That Are Supported by IIS 6.0 pg 21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19479-5' platform='iis6' modified='2013-02-11'>
      <description>The master home directory "Directory Browsing" permission should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Home Directory tab &gt; Directory Browsing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Cert-In Securing IIS 6.0 Web Server'>Table 6: Web Site Permissions That Are Supported by IIS 6.0 pg 21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19263-3' platform='iis6' modified='2013-02-11'>
      <description>The master home directory "Log Visits" permission should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Home Directory tab &gt; Log Visits</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Cert-In Securing IIS 6.0 Web Server'>Table 6: Web Site Permissions That Are Supported by IIS 6.0 pg 21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19322-7' platform='iis6' modified='2013-02-11'>
      <description>The master home directory "Index this resource" permission should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) none/scripts/scripts&amp;executables</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Home Directory tab &gt; Index this resource</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Cert-In Securing IIS 6.0 Web Server'>Table 6: Web Site Permissions That Are Supported by IIS 6.0 pg 21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19625-3' platform='iis6' modified='2013-02-11'>
      <description>The master home directory "Execute Permissions" permission should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Home Directory tab &gt; Execute Permissions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Cert-In Securing IIS 6.0 Web Server'>Table 6: Web Site Permissions That Are Supported by IIS 6.0 pg 21</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19903-4' platform='iis6' modified='2013-02-11'>
      <description>The master home directory "Anonymous Access" permission for IIS websites should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Directory Security &gt; Authentication and Access Control tab &gt; Anonymous Access</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Cert-In Securing IIS 6.0 Web Server'>4.2.2 Authentication pg 16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19259-1' platform='iis6' modified='2013-02-11'>
      <description>The master home directory "Basic Authentication" setting should be enabled or disabled.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Directory Security &gt; Authentication and Access Control tab &gt; Authenticated Access</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Cert-In Securing IIS 6.0 Web Server'>4.2.2 Authentication pg 16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19685-7' platform='iis6' modified='2013-02-11'>
      <description>The master home directory "Integrated Windows Authentication" setting should be enabled or disabled.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Directory Security &gt; Authentication and Access Control tab &gt; Authenticated Access</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Cert-In Securing IIS 6.0 Web Server'>4.2.2 Authentication pg 16</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19932-3' platform='iis6' modified='2013-02-11'>
      <description>The "Enable Logging" setting should be enabled or disabled for the specified web server</description>
      <parameters>
        <parameter>(1) TARGET: server</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Server &gt; Enable Logging</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Logs of web server access and errors must be established and maintained.
STIG ID: WG240 IIS6  Rule ID: SV-38065r1_rule  Vuln ID: V-2250</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19506-5' platform='iis6' modified='2013-02-11'>
      <description>The "Read" permission should be enabled or disabled as appropriate for the home directory of the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Read</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The IIS web site permissions "Write" or "Script Source" must not be selected.
STIG ID: WA000-WI092 IIS6  Rule ID: SV-38020r1_rule  Vuln ID: V-13699</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19406-8' platform='iis6' modified='2013-02-11'>
      <description>The "Write" privilege  should be enabled or disabled as appropriate for the home directory of the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Write</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The IIS web site permissions "Write" or "Script Source" must not be selected.
STIG ID: WA000-WI092 IIS6  Rule ID: SV-38020r1_rule  Vuln ID: V-13699</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20005-5' platform='iis6' modified='2013-02-11'>
      <description>The "Script Source Access" permission should be enabled or disabled as appropriate for the home directory of the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Home Directory tab &gt; Script Source</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The IIS web site permissions "Write" or "Script Source" must not be selected.
STIG ID: WA000-WI092 IIS6  Rule ID: SV-38020r1_rule  Vuln ID: V-13699</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19655-0' platform='iis6' modified='2013-02-11'>
      <description>The "Directory Browsing" permission should be enabled or disabled as appropriate for the home directory of the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Directory Browsing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Directory browsing must be disabled.
STIG ID: WA000-WI090 IIS6  Rule ID: SV-38016r1_rule  Vuln ID: V-6755</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19324-3' platform='iis6' modified='2013-02-11'>
      <description>The"Log Visits" permission should be enabled or disabled as appropriate for the home directory of the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Log Visits</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Logs of web server access and errors must be established and maintained.
STIG ID: WG240 IIS6  Rule ID: SV-38065r1_rule  Vuln ID: V-2250</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19092-6' platform='iis6' modified='2013-02-11'>
      <description>The  "Index this resource" permission should be enabled or disabled as appropriate for the home directory of the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Index this resource</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Indexing Services must only index web content.
STIG ID: WA000-WI070 IIS6  Rule ID: SV-38011r1_rule  Vuln ID: V-3963</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19716-0' platform='iis6' modified='2013-02-11'>
      <description>The "Execute Permissions" permission should be set correctly for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) none/scripts/scripts&amp;executables</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Execute Permissions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The web client account access to the content and scripts directories must be limited to read and execute.
STIG ID: WG290 IIS6  Rule ID: SV-30020r2_rule  Vuln ID: V-2258</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19138-7' platform='iis6' modified='2013-02-11'>
      <description>The  "Anonymous Access" permission should be enabled or disabled as appropriate for the home directory of the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Directory Security &gt; Authentication and Access Control tab &gt; Anonymous Access</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>https://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/035dcfd0-9a36-4788-b3b6-91dc6a9d9936.mspx?mfr=true</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19867-1' platform='iis6' modified='2013-02-11'>
      <description>Basic Authentication should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Right Click on Server &gt; Properties &gt; Directory Security &gt; Authentication and Access Control tab &gt; Authenticated Access</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>https://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/f85f0f16-4fea-4852-980c-4982d53c9948.mspx?mfr=true</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19628-7' platform='iis6' modified='2013-02-11'>
      <description>Integrated Windows Authentication should be enabled or disabled as appropriate the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager GUI: Server &gt; Right Click on the specified website &gt; Properties &gt; Directory Security &gt; Authentication and Access Control tab &gt; Authenticated Access</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>https://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/5f8fe119-4095-4094-bba5-7dec361c7afe.mspx?mfr=true</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19432-4' platform='iis6' modified='2013-02-11'>
      <description>The WWW service Special Characters In Shells setting should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\AllowSpecialCharsInShell</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://msdn.microsoft.com/en-us/library/aa711451%28v=vs.71%29.aspx</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19790-5' platform='iis6' modified='2013-02-11'>
      <description>IIS WWW service SSL error logging should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SecurityProviders\Schannel\EventLogging</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://support.microsoft.com/kb/260729</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20065-9' platform='iis6' modified='2013-02-11'>
      <description>The RDSServer.DataFactory object should be enable or disabeld as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\ADCLaunch\RDSServer.Factory</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://technet.microsoft.com/en-us/security/bulletin/fq99-025</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19711-1' platform='iis6' modified='2013-02-11'>
      <description>The AdvancedDataFactory object should be enable or disabeld as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\ADCLaunch\AdvancedDataFactory</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://technet.microsoft.com/en-us/security/bulletin/fq99-025</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19384-7' platform='iis6' modified='2013-02-11'>
      <description>The VbBusObj.VbBusObjCls object should be enable or disabeld as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\ADCLaunch\VbBusObj.VbBusObjCls</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://technet.microsoft.com/en-us/security/bulletin/fq99-025</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19690-7' platform='iis6' modified='2013-02-11'>
      <description>The execution context of the IIS CGI processes should be configured as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>'CreateProcessAsUser' key in IIS metabase file</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/7b55d524-60fc-4420-807b-e1797658088a.mspx?mfr=true</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20023-8' platform='iis6' modified='2013-02-11'>
      <description>The '.printer' extension mapping should be configured as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Configuration button &gt; App Mappings tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Unused and vulnerable script mappings in IIS 6 must be removed.
STIG ID: WA000-WI050 IIS6  Rule ID: SV-16145r2_rule  Vuln ID: V-2267</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19768-1' platform='iis6' modified='2013-02-11'>
      <description>The '.htw' extension mapping should be configured as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Configuration button &gt; App Mappings tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Unused and vulnerable script mappings in IIS 6 must be removed.
STIG ID: WA000-WI050 IIS6  Rule ID: SV-16145r2_rule  Vuln ID: V-2267</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19946-3' platform='iis6' modified='2013-02-11'>
      <description>The '.ida' extension mapping should be configured as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Configuration button &gt; App Mappings tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Unused and vulnerable script mappings in IIS 6 must be removed.
STIG ID: WA000-WI050 IIS6  Rule ID: SV-16145r2_rule  Vuln ID: V-2267</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19365-6' platform='iis6' modified='2013-02-11'>
      <description>The '.idq' extension mapping should be configured as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Configuration button &gt; App Mappings tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Unused and vulnerable script mappings in IIS 6 must be removed.
STIG ID: WA000-WI050 IIS6  Rule ID: SV-16145r2_rule  Vuln ID: V-2267</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19527-1' platform='iis6' modified='2013-02-11'>
      <description>The '.idc' extension mapping should be configured as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Configuration button &gt; App Mappings tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Unused and vulnerable script mappings in IIS 6 must be removed.
STIG ID: WA000-WI050 IIS6  Rule ID: SV-16145r2_rule  Vuln ID: V-2267</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19732-7' platform='iis6' modified='2013-02-11'>
      <description>The '.shtm' extension mapping should be configured as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Configuration button &gt; App Mappings tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Unused and vulnerable script mappings in IIS 6 must be removed.
STIG ID: WA000-WI050 IIS6  Rule ID: SV-16145r2_rule  Vuln ID: V-2267</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20043-6' platform='iis6' modified='2013-02-11'>
      <description>The '.stm' extension mapping should be configured as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Configuration button &gt; App Mappings tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Unused and vulnerable script mappings in IIS 6 must be removed.
STIG ID: WA000-WI050 IIS6  Rule ID: SV-16145r2_rule  Vuln ID: V-2267</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19545-3' platform='iis6' modified='2013-02-11'>
      <description>The '.shtml' extension mapping should be configured as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Configuration button &gt; App Mappings tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Unused and vulnerable script mappings in IIS 6 must be removed.
STIG ID: WA000-WI050 IIS6  Rule ID: SV-16145r2_rule  Vuln ID: V-2267</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20044-4' platform='iis6' modified='2013-02-11'>
      <description>Relative path traversal should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: webiste</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Configuration button &gt; Enable Parent Paths</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Interactive scripts must have proper access controls.
STIG ID: WG410 IIS6  Rule ID: SV-28848r2_rule  Vuln ID: V-2229</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19751-7' platform='iis6' modified='2013-02-11'>
      <description>The startup type of the IIS Admin (IISAdmin) service should be correct.</description>
      <parameters>
        <parameter>(1) automatic/manual/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the Services Administrative Tool </technical_mechanism>
        <technical_mechanism>(2) definied by Group Policy</technical_mechanism>
        <technical_mechanism>(3) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IISADMIN\Start</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/2df6ff66-da04-4e7c-997d-8f7aa46af8c8.mspx?mfr=true</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20034-5' platform='iis6' modified='2013-02-11'>
      <description>Permissions on the Inetpub directory should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 IIS6  Rule ID: SV-38327r1_rule  Vuln ID: V-2259</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19792-1' platform='iis6' modified='2013-02-11'>
      <description>Permissions on the inetsrv directory should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 IIS6  Rule ID: SV-38327r1_rule  Vuln ID: V-2259</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20014-7' platform='iis6' modified='2013-02-11'>
      <description>Permissions on  inetsrv\asp.dll should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 IIS6  Rule ID: SV-38327r1_rule  Vuln ID: V-2259</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19433-2' platform='iis6' modified='2013-02-11'>
      <description>Permissions on the Web Root "Images" directory should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 IIS6  Rule ID: SV-38327r1_rule  Vuln ID: V-2259</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19643-6' platform='iis6' modified='2013-02-11'>
      <description>Permissions on the Web Root "scripts" directory should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 IIS6  Rule ID: SV-38327r1_rule  Vuln ID: V-2259</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19332-6' platform='iis6' modified='2013-02-11'>
      <description>Permissions on the Web Root "executables" directory should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 IIS6  Rule ID: SV-38327r1_rule  Vuln ID: V-2259</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20083-2' platform='iis6' modified='2013-02-11'>
      <description>Permissions on the Web Root "docs" directory should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 IIS6  Rule ID: SV-38327r1_rule  Vuln ID: V-2259</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19801-0' platform='iis6' modified='2013-02-11'>
      <description>Permissions on the Web Root "home" directory should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 IIS6  Rule ID: SV-38327r1_rule  Vuln ID: V-2259</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19618-8' platform='iis6' modified='2013-02-11'>
      <description>Permissions on the Web Root "include" directory should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 IIS6  Rule ID: SV-38327r1_rule  Vuln ID: V-2259</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20052-7' platform='iis6' modified='2013-02-11'>
      <description>Permissions on the Web Root directory should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 IIS6  Rule ID: SV-38327r1_rule  Vuln ID: V-2259</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19888-7' platform='iis6' modified='2013-02-11'>
      <description>Permissions on the default Logfiles directory should be set appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) list of permissions (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Web server system files must conform to minimum file permission requirements.
STIG ID: WG300 IIS6  Rule ID: SV-38327r1_rule  Vuln ID: V-2259</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20077-4' platform='iis6' modified='2013-02-11'>
      <description>The file auditing for the directory \%SystemRoot%\System32\Inetsrv should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) events to  audit (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's SACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/ebf1885b-7217-4ac6-93a3-633ef248bc8f.mspx?mfr=true</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19977-8' platform='iis6' modified='2013-02-11'>
      <description>The file auditing for the Inetpub  directory should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) events to  audit (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's SACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/ebf1885b-7217-4ac6-93a3-633ef248bc8f.mspx?mfr=true</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20029-5' platform='iis6' modified='2013-02-11'>
      <description>The file auditing for the Web Root directory should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) events to  audit (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's SACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/ebf1885b-7217-4ac6-93a3-633ef248bc8f.mspx?mfr=true</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19884-6' platform='iis6' modified='2013-02-11'>
      <description>HTTP protocol logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/676400bc-8969-4aa7-851a-9319490a9bbb.mspx?mfr=true</reference>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Log file data must contain required data elements.
STIG ID: WG242 IIS6  Rule ID: SV-28653r2_rule  Vuln ID: V-13688
Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20024-6' platform='iis6' modified='2013-02-11'>
      <description>Date logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/676400bc-8969-4aa7-851a-9319490a9bbb.mspx?mfr=true</reference>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Log file data must contain required data elements.
STIG ID: WG242 IIS6  Rule ID: SV-28653r2_rule  Vuln ID: V-13688
Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19615-4' platform='iis6' modified='2013-02-11'>
      <description>Time logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/676400bc-8969-4aa7-851a-9319490a9bbb.mspx?mfr=true</reference>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Log file data must contain required data elements.
STIG ID: WG242 IIS6  Rule ID: SV-28653r2_rule  Vuln ID: V-13688
Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19678-2' platform='iis6' modified='2013-02-11'>
      <description>Client IP Address logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/676400bc-8969-4aa7-851a-9319490a9bbb.mspx?mfr=true</reference>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Log file data must contain required data elements.
STIG ID: WG242 IIS6  Rule ID: SV-28653r2_rule  Vuln ID: V-13688
Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19753-3' platform='iis6' modified='2013-02-11'>
      <description>User name logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/676400bc-8969-4aa7-851a-9319490a9bbb.mspx?mfr=true</reference>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Log file data must contain required data elements.
STIG ID: WG242 IIS6  Rule ID: SV-28653r2_rule  Vuln ID: V-13688
Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19683-2' platform='iis6' modified='2013-02-11'>
      <description>User agent logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/676400bc-8969-4aa7-851a-9319490a9bbb.mspx?mfr=true</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19167-6' platform='iis6' modified='2013-02-11'>
      <description>Method logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/676400bc-8969-4aa7-851a-9319490a9bbb.mspx?mfr=true</reference>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Log file data must contain required data elements.
STIG ID: WG242 IIS6  Rule ID: SV-28653r2_rule  Vuln ID: V-13688
Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20028-7' platform='iis6' modified='2013-02-11'>
      <description>URI stem logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/676400bc-8969-4aa7-851a-9319490a9bbb.mspx?mfr=true</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19606-3' platform='iis6' modified='2013-02-11'>
      <description>URL query logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/676400bc-8969-4aa7-851a-9319490a9bbb.mspx?mfr=true</reference>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Log file data must contain required data elements.
STIG ID: WG242 IIS6  Rule ID: SV-28653r2_rule  Vuln ID: V-13688
Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19838-2' platform='iis6' modified='2013-02-11'>
      <description>Server IP address logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/676400bc-8969-4aa7-851a-9319490a9bbb.mspx?mfr=true</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19684-0' platform='iis6' modified='2013-02-11'>
      <description>Server port logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/676400bc-8969-4aa7-851a-9319490a9bbb.mspx?mfr=true</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19940-6' platform='iis6' modified='2013-02-11'>
      <description>Protocol status logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/676400bc-8969-4aa7-851a-9319490a9bbb.mspx?mfr=true</reference>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Log file data must contain required data elements.
STIG ID: WG242 IIS6  Rule ID: SV-28653r2_rule  Vuln ID: V-13688
Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20080-8' platform='iis6' modified='2013-02-11'>
      <description>Win32 status logging should be enabled or disabled as appropriate for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; W3C Extended Log File Format &gt; Properties &gt; Extended Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/676400bc-8969-4aa7-851a-9319490a9bbb.mspx?mfr=true</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20026-1' platform='iis6' modified='2013-02-11'>
      <description>The path of the HTTP Log folder  should be configured correctly for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) local path</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Service Manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Website Tab &gt; Properties</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://msdn.microsoft.com/en-us/library/ff648653.aspx</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19641-0' platform='iis6' modified='2013-02-11'>
      <description>The file auditing for the \Metaback directory should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts (2) events to  audit (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's SACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://support.microsoft.com/kb/271071</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19362-3' platform='iis6' modified='2013-02-11'>
      <description>The membership of the IUSR account should be configured correctly.</description>
      <parameters>
        <parameter>(1) set of accounts</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by Local or Group Policy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Anonymous access accounts must be restricted.
STIG ID: WG195 IIS6  Rule ID: SV-29351r2_rule  Vuln ID: V-6537
Severity: CAT I Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19611-3' platform='iis6' modified='2013-02-11'>
      <description>The IUSR account should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by Local or Group Policy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://msdn.microsoft.com/en-us/library/ff648653.aspx</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20015-4' platform='iis6' modified='2013-02-11'>
      <description>The IWAM account should be configured correctly.</description>
      <parameters>
        <parameter>(1) valid name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>WAMUserName Metabase Property</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/8f8364a3-5d84-48fd-b6a7-044dad20c413.mspx?mfr=true</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19988-5' platform='iis6' modified='2013-02-11'>
      <description>Server Side Includes command shell should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1)  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters\SSIEnableCmdDirective</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-19691-5' platform='iis6' modified='2013-02-11'>
      <description>Web-based password reset IIS application mappings (.htr) should be configured correctly.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Service manager &gt; Server &gt; Right Click on the specified website &gt; Properties &gt; Home Directory tab &gt; Configuration button &gt;App Mappings tab</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  Unused and vulnerable script mappings in IIS 6 must be removed.
STIG ID: WA000-WI050 IIS6  Rule ID: SV-16145r2_rule  Vuln ID: V-2267</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20020-4' platform='iis6' modified='2013-02-11'>
      <description>IIS Sample files should be installed or not as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism> files in \Inetpub\iissamples</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  All web server documentation, sample code, example applications, and tutorials must be removed from a production web server.
STIG ID: WG385 IIS6  Rule ID: SV-38330r1_rule  Vuln ID: V-13621</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19737-6' platform='iis6' modified='2013-02-11'>
      <description>The sample Data Access files should be installed or not as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) files in \Program Files\Common Files\System\msadc\Samples</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  All web server documentation, sample code, example applications, and tutorials must be removed from a production web server.
STIG ID: WG385 IIS6  Rule ID: SV-38330r1_rule  Vuln ID: V-13621</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19956-2' platform='iis6' modified='2013-02-11'>
      <description>IIS Help files should be installed or not as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) files in %SystemRoot%\help\iishelp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  All web server documentation, sample code, example applications, and tutorials must be removed from a production web server.
STIG ID: WG385 IIS6  Rule ID: SV-38330r1_rule  Vuln ID: V-13621</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19797-0' platform='iis6' modified='2013-02-11'>
      <description>Remote Account password changes should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1)  AuthChangeDisable flag in the Metabase</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The IISADMPWD directory must be removed from the Web server.
STIG ID: WA000-WI035 IIS6  Rule ID: SV-38148r1_rule  Vuln ID: V-13698
Severity: CAT I Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19991-9' platform='iis6' modified='2013-02-11'>
      <description>IIS sample Web Printing files should be installed or not as appropriate.</description>
      <parameters>
        <parameter>(1) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism> files in %SystemRoot%\web\printers</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  All web server documentation, sample code, example applications, and tutorials must be removed from a production web server.
STIG ID: WG385 IIS6  Rule ID: SV-38330r1_rule  Vuln ID: V-13621</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19763-2' platform='iis6' modified='2013-02-11'>
      <description>The "AllowRestrictedChars" setting should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HTTP\Parameters\AllowRestrictedChars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The AllowRestrictedChars registry key must be disabled.
STIG ID: WA000-WI6080 IIS6  Rule ID: SV-38160r1_rule  Vuln ID: V-13714</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19713-7' platform='iis6' modified='2013-02-11'>
      <description>The "EnableNonUTF8" setting should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HTTP\Parameters\EnableNonUTF8</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The EnableNonUTF8 registry key must be disabled.
STIG ID: WA000-WI6082 IIS6  Rule ID: SV-38161r1_rule  Vuln ID: V-13715</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19270-8' platform='iis6' modified='2013-02-11'>
      <description>The "FavorUTF8" setting should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HTTP\Parameters\FavorUTF8</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The FavorUTF8 registry key must be set properly.
STIG ID: WA000-WI6084 IIS6  Rule ID: SV-38162r1_rule  Vuln ID: V-13716</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19942-2' platform='iis6' modified='2013-02-11'>
      <description>The maximum possible size of request headers should be set correctly.</description>
      <parameters>
        <parameter>(1) number of bytes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HTTP\Parameters\MaxFieldLength</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The MaxFieldLength registry entry must be set properly.
STIG ID: WA000-WI6086 IIS6  Rule ID: SV-38163r1_rule  Vuln ID: V-13717</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19665-9' platform='iis6' modified='2013-02-11'>
      <description>The maximum possible combined size of request line and headers should be set correctly.</description>
      <parameters>
        <parameter>(1) number of bytes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HTTP\Parameters\MaxRequestBytes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The MaxRequestBytes registry entry must be set properly.
STIG ID: WA000-WI6088 IIS6  Rule ID: SV-38164r1_rule  Vuln ID: V-13718</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19860-6' platform='iis6' modified='2013-02-11'>
      <description>The maximum number of characters in a URL path setting should be set correctly.</description>
      <parameters>
        <parameter>(1) number of characters</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HTTP\Parameters\UrlSegmentMaxLength</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The UrlSegmentMaxLength registry entry must be set properly.
STIG ID: WA000-WI6090 IIS6  Rule ID: SV-38165r1_rule  Vuln ID: V-13719</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19823-4' platform='iis6' modified='2013-02-11'>
      <description>The maximum number of URL path segments should be set correctly.</description>
      <parameters>
        <parameter>(1) number of URL path segments</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HTTP\Parameters\UrlSegmentMaxCount</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The UrlSegmentMaxCount registry entry must be set properly.
STIG ID: WA000-WI6096 IIS6  Rule ID: SV-38168r1_rule  Vuln ID: V-13722</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19843-2' platform='iis6' modified='2013-02-11'>
      <description>The allowance of %U notation in request URLs should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HTTP\Parameters\PercentUAllowed</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The PercentUAllowed registry entry must be set properly.
STIG ID: WA000-WI6092 IIS6  Rule ID: SV-38166r1_rule  Vuln ID: V-13720</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19799-6' platform='iis6' modified='2013-02-11'>
      <description>The maximum response size that can be cached in the kernel should be set correctly.</description>
      <parameters>
        <parameter>(1) number of bytes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\HTTP\Parameters\UriMaxUriBytes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Server  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The UriMaxUriBytes registry entry must be set properly.
STIG ID: WA000-WI6094 IIS6  Rule ID: SV-38167r1_rule  Vuln ID: V-13721</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20067-5' platform='iis6' modified='2013-02-11'>
      <description>The maximum size of the entire request body setting should be set correctly.</description>
      <parameters>
        <parameter>(1) number of bytes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>MaxRequestEntityAllowed key in IIS metabase file</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The MaxRequestEntityAllowed metabase value must be defined.
STIG ID: WA000-WI6098 IIS6  Rule ID: SV-38047r1_rule  Vuln ID: V-13723</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19097-5' platform='iis6' modified='2013-02-11'>
      <description>The URLScan ISAPI filters should be configured correctly for the specified websites.</description>
      <parameters>
        <parameter>(1) TARGET: website</parameter>
        <parameter>(2) exist/not exist</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manage =&gt; Web Sites =&gt;&lt;Web Site&gt; =&gt; right click Properties =&gt; ISAPI Filters =&gt; URLScan</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/f9b564d2-d245-4241-ba0d-266a896ca663.mspx?mfr=true</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20046-9' platform='iis6' modified='2013-02-11'>
      <description>The 'Replace a process-level token' setting should be configured as appropriate.</description>
      <parameters>
        <parameter>(1) set of accounts</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the 'User Rights Assignment' setting in Local Policy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/3648346f-e4f5-474b-86c7-5a86e85fa1ff.mspx?mfr=true</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19288-0' platform='iis6' modified='2013-02-11'>
      <description>The "Adjust memory quotas for a process" setting should be configured appropriatly.</description>
      <parameters>
        <parameter>(1) set of accounts</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) </technical_mechanism>
        <technical_mechanism>defined by the 'Adjust memory quotas for a process' setting in Local Policy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/3648346f-e4f5-474b-86c7-5a86e85fa1ff.mspx?mfr=true</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20091-5' platform='iis6' modified='2013-02-11'>
      <description>The startup type of the HTTP SSL (HTTPFilter) service should be configured correctly.</description>
      <parameters>
        <parameter>(1) automatic/manual/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the Services Administrative Tool (2) definied by Group Policy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/2df6ff66-da04-4e7c-997d-8f7aa46af8c8.mspx?mfr=true</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19840-8' platform='iis6' modified='2013-02-11'>
      <description>The identity of the IIS Application Pools service should be set correctly.</description>
      <parameters>
        <parameter>(1) type of service</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager =&gt; Application Pools =&gt; right click Prpoerties =&gt; Identity Tab =&gt; non-privileged account</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The web site must have a unique application pool.
STIG ID: WA000-WI6010 IIS6  Rule ID: SV-38137r1_rule  Vuln ID: V-13703</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19954-7' platform='iis6' modified='2013-02-11'>
      <description>The worker proceess isolation should be configured appropriatly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager =&gt; Web Sites =&gt; right click Properties =&gt; Services =&gt; Run WWW service in IIS 5.0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/ed3c22ba-39fc-4332-bdb7-a0d9c76e4355.mspx?mfr=true</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19157-7' platform='iis6' modified='2013-02-11'>
      <description>The IIS Application Pool "Recycle worker process (in minutes)" setting should be enabled or disabled as appropriate for the specified application pools.</description>
      <parameters>
        <parameter>(1) TARGET: application pool</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager =&gt;  Application Pools =&gt; &lt;Application Pool&gt; =&gt; right click Properties =&gt; Recycling =&gt; Recycle worker processes (in minutes)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>The Recycle Worker processes in minutes monitor must be set properly.
STIG ID: WA000-WI6020 IIS6  Rule ID: SV-38134r1_rule  Vuln ID: V-13704</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19414-2' platform='iis6' modified='2013-02-11'>
      <description>The IIS Application Pool "Recycle worker process (in minutes)" setting should be set as appropriate for the specified application pools.</description>
      <parameters>
        <parameter>(1) TARGET: application pool</parameter>
        <parameter>(2) number of minutes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager =&gt;  Application Pools =&gt; &lt;Application Pool&gt; =&gt; right click Properties =&gt; Recycling =&gt; Recycle worker processes (in minutes)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>The Recycle Worker processes in minutes monitor must be set properly.
STIG ID: WA000-WI6020 IIS6  Rule ID: SV-38134r1_rule  Vuln ID: V-13704</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20054-3' platform='iis6' modified='2013-02-11'>
      <description>The IIS Application Pool "Recycle worker process (number of requests)" setting should be enabled or disabled as appropriate for the specified application pools.</description>
      <parameters>
        <parameter>(1) TARGET: application pool</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager =&gt;  Application Pools =&gt; &lt;Application Pool&gt; =&gt; right click Properties =&gt; Recycling =&gt; Recycle worker processes (number of requests)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The maximum number of requests an application pool can process must be set.
STIG ID: WA000-WI6022 IIS6  Rule ID: SV-38132r1_rule  Vuln ID: V-13705</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19672-5' platform='iis6' modified='2013-02-11'>
      <description>The IIS Application Pool "Recycle worker process (number of requests)" setting should be set as appropriate for the specified application pools.</description>
      <parameters>
        <parameter>(1) TARGET: application pool</parameter>
        <parameter>(2) number of requests</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager =&gt;  Application Pools =&gt; &lt;Application Pool&gt; =&gt; right click Properties =&gt; Recycling =&gt; Recycle worker processes (number of requests)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The maximum number of requests an application pool can process must be set.
STIG ID: WA000-WI6022 IIS6  Rule ID: SV-38132r1_rule  Vuln ID: V-13705</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19934-9' platform='iis6' modified='2013-02-11'>
      <description>The IIS Application Pool "Maximum virtual memory (in megabytes)" setting should be enabled or disabled as appropriate for the specified application pools.</description>
      <parameters>
        <parameter>(1) TARGET: application pool</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager =&gt;  Application Pools =&gt; &lt;Application Pool&gt; =&gt; right click Properties =&gt; Recycling =&gt; Maximum virtual memory (in megabytes)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The maximum virtual memory monitor must be enabled.
STIG ID: WA000-WI6024 IIS6  Rule ID: SV-38033r1_rule  Vuln ID: V-13706</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19437-3' platform='iis6' modified='2013-02-11'>
      <description>The IIS Application Pool "Maximum virtual memory (in megabytes)" setting should be set correctly for the specified application pools.</description>
      <parameters>
        <parameter>(1) TARGET: application pool</parameter>
        <parameter>(2) number of megabytes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager =&gt;  Application Pools =&gt; &lt;Application Pool&gt; =&gt; right click Properties =&gt; Recycling =&gt; Maximum virtual memory (in megabytes)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The maximum virtual memory monitor must be enabled.
STIG ID: WA000-WI6024 IIS6  Rule ID: SV-38033r1_rule  Vuln ID: V-13706</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19633-7' platform='iis6' modified='2013-02-11'>
      <description>The IIS Application Pool "Maximum used memory (in megabytes)" setting should be enabled or disabled as appropriate for the specified application pools.</description>
      <parameters>
        <parameter>(1) TARGET: application pool</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager =&gt;  Application Pools =&gt; &lt;Application Pool&gt; =&gt; right click Properties =&gt; Recycling =&gt; Maximum used memory (in megabytes)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The maximum used memory monitor must be enabled.
STIG ID: WA000-WI6026 IIS6  Rule ID: SV-38130r1_rule  Vuln ID: V-13707</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20004-8' platform='iis6' modified='2013-02-11'>
      <description>The IIS Application Pool "Maximum used memory (in megabytes)" setting should be set correctly for the specified application pools.</description>
      <parameters>
        <parameter>(1) TARGET: application pool</parameter>
        <parameter>(2) number of megabytes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager =&gt;  Application Pools =&gt; &lt;Application Pool&gt; =&gt; right click Properties =&gt; Recycling =&gt; Maximum used memory (in megabytes)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The maximum used memory monitor must be enabled.
STIG ID: WA000-WI6026 IIS6  Rule ID: SV-38130r1_rule  Vuln ID: V-13707</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19442-3' platform='iis6' modified='2013-02-11'>
      <description>The IIS Application Pool "Shutdown worker processes after being idle (time in minutes)" setting should be enabled or disabled as appropriate for the specified application pools.</description>
      <parameters>
        <parameter>(1) TARGET: application pool</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager =&gt;  Application Pools =&gt; &lt;Application Pool&gt; =&gt; right click Properties =&gt; Performance =&gt; Shutdown worker processes after being idle (time in minutes)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The Shutdown worker processes Idle Timeout monitor must be enabled.
STIG ID: WA000-WI6028 IIS6  Rule ID: SV-38125r1_rule  Vuln ID: V-13708</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19597-4' platform='iis6' modified='2013-02-11'>
      <description>The IIS Application Pool "Shutdown worker processes after being idle (time in minutes)" setting should be set correctly for the specified application pools.</description>
      <parameters>
        <parameter>(1) TARGET: application pool</parameter>
        <parameter>(2) number of minutes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager =&gt;  Application Pools =&gt; &lt;Application Pool&gt; =&gt; right click Properties =&gt; Performance =&gt; Shutdown worker processes after being idle (time in minutes)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The Shutdown worker processes Idle Timeout monitor must be enabled.
STIG ID: WA000-WI6028 IIS6  Rule ID: SV-38125r1_rule  Vuln ID: V-13708</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19912-5' platform='iis6' modified='2013-02-11'>
      <description>The IIS Application Pool "Limit the kernel request queue (number of requests)" setting should be enabled or disabled as appropriate for the specified application pools.</description>
      <parameters>
        <parameter>(1) TARGET: application pool</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager =&gt;  Application Pools =&gt; &lt;Application Pool&gt; =&gt; right click Properties =&gt; Performance =&gt; Limit the kernel request queue (number of requests)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The Limit the kernel request queue monitor must be enabled
STIG ID: WA000-WI6030 IIS6  Rule ID: SV-38123r1_rule  Vuln ID: V-13709</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20002-2' platform='iis6' modified='2013-02-11'>
      <description>The IIS Application Pool "Limit the kernel request queue (number of requests)" setting should be set correctly for the specified application pools.</description>
      <parameters>
        <parameter>(1) TARGET: application pool</parameter>
        <parameter>(2) number of requests</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager =&gt;  Application Pools =&gt; &lt;Application Pool&gt; =&gt; right click Properties =&gt; Performance =&gt; Limit the kernel request queue (number of requests)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The Limit the kernel request queue monitor must be enabled
STIG ID: WA000-WI6030 IIS6  Rule ID: SV-38123r1_rule  Vuln ID: V-13709</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19160-1' platform='iis6' modified='2013-02-11'>
      <description>The IIS Application Pool "'Enable pinging" setting should be enabled or disabled as appropriate for the specified application pools..</description>
      <parameters>
        <parameter>(1) TARGET: application pool</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager =&gt;  Application Pools =&gt; &lt;Application Pool&gt; =&gt; right click Properties =&gt; Health =&gt; Enable pinging</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The Enable pinging monitor must be enabled.
STIG ID: WA000-WI6032 IIS6  Rule ID: SV-38043r1_rule  Vuln ID: V-13710</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20073-3' platform='iis6' modified='2013-02-11'>
      <description>The IIS Application Pool "Ping worker process every (frequency in seconds)" setting should be set correctly for the specified application pools.</description>
      <parameters>
        <parameter>(1) TARGET: application pool</parameter>
        <parameter>(2) number of seconds</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager =&gt;  Application Pools =&gt; &lt;Application Pool&gt; =&gt; right click Properties =&gt; Health =&gt; Ping worker process every (frequency in seconds)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The Enable pinging monitor must be enabled.
STIG ID: WA000-WI6032 IIS6  Rule ID: SV-38043r1_rule  Vuln ID: V-13710</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20069-1' platform='iis6' modified='2013-02-11'>
      <description>The IIS Application Pool "Enable rapid-fail protection" setting should be enabled or disabled as appropriate for the specified application pools.</description>
      <parameters>
        <parameter>(1) TARGET: application pool</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager =&gt;  Application Pools =&gt; &lt;Application Pool&gt; =&gt; right click Properties =&gt; Health =&gt; Enable rapid-fail protection</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The Enable rapid-fail protection monitor must be enabled.
STIG ID: WA000-WI6034 IIS6  Rule ID: SV-38044r1_rule  Vuln ID: V-13711</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20141-8' platform='iis6' modified='2013-02-11'>
      <description>The IIS Application Pool "Enable rapid-fail protection - Failures" setting should be set correctly for the specified application pools.</description>
      <parameters>
        <parameter>(1) TARGET: application pool</parameter>
        <parameter>(2) number of failures</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager =&gt;  Application Pools =&gt; &lt;Application Pool&gt; =&gt; right click Properties =&gt; Health =&gt; Enable rapid-fail protection - Failures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The Enable rapid-fail protection monitor must be enabled.
STIG ID: WA000-WI6034 IIS6  Rule ID: SV-38044r1_rule  Vuln ID: V-13711</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20055-0' platform='iis6' modified='2013-02-11'>
      <description>The IIS Application Pool "Enable rapid-fail protection - Time Period" setting should be set correctly for the specified application pools.</description>
      <parameters>
        <parameter>(1) TARGET: application pool</parameter>
        <parameter>(2) number of minutes</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Internet Information Services (IIS) Manager =&gt;  Application Pools =&gt; &lt;Application Pool&gt; =&gt; right click Properties =&gt; Health =&gt; Enable rapid-fail protection - Time Period</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='STIG IIS6 Site  Version: 6  Release: 13 Benchmark Date: 28 Oct 2011'>Rule Title:  The Enable rapid-fail time period monitor must be enabled.
STIG ID: WA000-WI6036 IIS6  Rule ID: SV-38045r1_rule  Vuln ID: V-13712</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19927-3' platform='iis6' modified='2013-02-11'>
      <description>The required auditing settings for the MetaBase.xml file should be assigned for the specified websites.</description>
      <parameters>
        <parameter>(1) set of accounts (2) events to  audit (3) applicability</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's SACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Online Documentation'>http://msdn.microsoft.com/en-us/library/ff648653.aspx</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20013-9' platform='ms-sql2000' modified='2013-02-11'>
      <description>Application object owner accounts for a specified database should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) ALTER LOGIN</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) login_name</technical_mechanism>
        <technical_mechanism>(2) enable/disable</technical_mechanism>
        <technical_mechanism>(3) default_database</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0005683 Rule Title: Application object owner accounts should be disabled when not performing installation or maintenance actions. STIG ID: DG0004 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19816-8' platform='ms-sql2000' modified='2013-02-11'>
      <description>Application object owner accounts for a specified database should be configured appropriately.</description>
      <parameters>
        <parameter>(1)From the query prompt:</parameter>
        <parameter>    USE [database name]</parameter>
        <parameter>    SELECT DISTINCT u.name</parameter>
        <parameter>    FROM sysusers u, sysobjects o</parameter>
        <parameter>    WHERE u.uid = o.uid</parameter>
        <parameter>    AND u.uid NOT IN ('1', '3', '4')</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) set of accounts</technical_mechanism>
        <technical_mechanism>(2) database name</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015607 Rule Title: Application objects should be owned by accounts authorized for ownership. STIG ID: DG0008 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19517-2' platform='ms-sql2000' modified='2013-02-11'>
      <description>Database application permissions allowing DDL statements to modify the application schema for a specified database should be configured appropriately.</description>
      <parameters>
        <parameter>(1) USE [database name]</parameter>
        <parameter>      SELECT USER_NAME(uid), name, crdate</parameter>
        <parameter>      FROM sysobjects</parameter>
        <parameter>      WHERE uid NOT IN (1, 3, 4)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) list of permissons                                                                     </technical_mechanism>
        <technical_mechanism>(2) set of accounts</technical_mechanism>
        <technical_mechanism>(3) database name</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0003727 Rule Title: Database applications should be restricted from using static DDL statements to modify the application schema for a specified database. STIG ID: DG0015 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19448-0' platform='ms-sql2000' modified='2013-02-11'>
      <description>Custom and GOTS application source code for a specified databased should be encrypted or not encrypted as appropriate.</description>
      <parameters>
        <parameter>(1) ALTER PROCEDURE</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) [procedure name]</technical_mechanism>
        <technical_mechanism>(2) WITH ENCRYPTION</technical_mechanism>
        <technical_mechanism>(3) Custom/GOTS procedures</technical_mechanism>
        <technical_mechanism>(4) Database Name</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0003823 Rule Title: Custom and GOTS application source code stored in the database should be protected with encryption or encoding. STIG ID: DG0091 Severity: CAT III Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19649-3' platform='ms-sql2000' modified='2013-02-11'>
      <description>Permissions on system tables for a specified database should be configured appropriately</description>
      <parameters>
        <parameter>(1) REVOKE / GRANT</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) list of permissons</technical_mechanism>
        <technical_mechanism>(2) [object]</technical_mechanism>
        <technical_mechanism>(3) [user name]</technical_mechanism>
        <technical_mechanism>(4) [database name]</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002458 Rule Title: Permissions on system tables should be restricted to authorized accounts. STIG ID: DM1749 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19926-5' platform='ms-sql2000' modified='2013-02-11'>
      <description>DDL permissions for a specified database and specified account should be configured appropriately</description>
      <parameters>
        <parameter>(1) CREATE</parameter>
        <parameter>(2) ALTER</parameter>
        <parameter>(3) DROP</parameter>
        <parameter>(1) REVOKE/GRANT CONTROL</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) set of accounts</technical_mechanism>
        <technical_mechanism>(2) list of permissions </technical_mechanism>
        <technical_mechanism>(3) database name</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002463 Rule Title: DDL permissions should be granted only to authorized accounts. STIG ID: DM1760 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19822-6' platform='ms-sql2000' modified='2013-02-11'>
      <description>Permissions using the WITH GRANT OPTION for a specified database should be configured appropriately</description>
      <parameters>
        <parameter>(1) REVOKE / GRANT</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) list of permissons</technical_mechanism>
        <technical_mechanism>(2) [object]</technical_mechanism>
        <technical_mechanism>(3) [user name]</technical_mechanism>
        <technical_mechanism>(4) [database name]</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002498 Rule Title : Permissions using the WITH GRANT OPTION should be granted only to DBA or application administrator accounts. STIG ID: DM5144 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19220-3' platform='ms-sql2000' modified='2013-02-11'>
      <description>Object permissions assigned to PUBLIC or GUEST for a specified database should be configured appropriately.</description>
      <parameters>
        <parameter>(1) REVOKE / GRANT</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) list of permissons</technical_mechanism>
        <technical_mechanism>(2) [object]</technical_mechanism>
        <technical_mechanism>(3) [public or guest]</technical_mechanism>
        <technical_mechanism>(4) dtaabase name</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015172 Rule Title: Object permissions should not be assigned to PUBLIC or GUEST. STIG ID: DM6196</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19886-1' platform='ms-sql2000' modified='2013-02-11'>
      <description>Access to DBMS software files and directories should be configured appropriately.</description>
      <parameters>
        <parameter>(1) defined by the object's DACL</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) set of accounts </technical_mechanism>
        <technical_mechanism>(2) list of permissions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015608 Rule Title: Access to DBMS software files and directories should not be granted to unauthorized users. STIG ID: DG0009 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19147-8' platform='ms-sql2000' modified='2013-02-11'>
      <description>Default demonstration and sample database objects and applications should be available or removed as appropriate.</description>
      <parameters>
        <parameter>(1) DROP DATABASE</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) database_name </technical_mechanism>
        <technical_mechanism>(2) database_snapshot_name</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015609 Rule Title: Default demonstration and sample database objects and applications should be removed. STIG ID: DG0014 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19909-1' platform='ms-sql2000' modified='2013-02-11'>
      <description>Required auditing parameters for database auditing should be set appropriately</description>
      <parameters>
        <parameter>(1) EXEC SP_TRACE_SETSTATUS</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) TraceID</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0005685 Rule Title: Required auditing parameters for database auditing should be set. STIG ID: DG0029 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19687-3' platform='ms-sql2000' modified='2013-02-11'>
      <description>DBMS privileges to restore database data or other DBMS configurations, features or objects in a specified database should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Use the SQL command to assign permissions to the appropriate roles</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) database name</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015107 Rule Title: DBMS privileges to restore database data or other DBMS configurations, features or objects should be restricted to authorized DBMS accounts. STIG ID: DG0063 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19392-0' platform='ms-sql2000' modified='2013-02-11'>
      <description>DBMS login account password complexity requirements should be configured appropriately</description>
      <parameters>
        <parameter>(1) ALTER LOGIN</parameter>
        <parameter>(2) CHECK_POLICY</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) login name</technical_mechanism>
        <technical_mechanism>(2) on/off</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015152 Rule Title: DBMS login accounts require passwords to meet complexity requirements. STIG ID: DG0079 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19857-2' platform='ms-sql2000' modified='2013-02-11'>
      <description>Passwords for DBMS default accounts should be set appropriately</description>
      <parameters>
        <parameter>(1) ALTER LOGIN</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) username</technical_mechanism>
        <technical_mechanism>(2) WITH PASSWORD [ new password ]</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015635 Rule Title: DBMS default accounts should be assigned custom passwords. STIG ID: DG0128 Severity: CAT I Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19749-1' platform='ms-sql2000' modified='2013-02-11'>
      <description>Remote DBMS administration should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) EXEC SP_CONFIGURE</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) remote admin connections</technical_mechanism>
        <technical_mechanism>(2) enable/disable</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015651 Rule Title: Remote DBMS administration should be documented and authorized or disabled. STIG ID: DG0157 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19781-4' platform='ms-sql2000' modified='2013-02-11'>
      <description>C2 Audit records should be configured appropriately</description>
      <parameters>
        <parameter>(1) EXEC SP_CONFIGURE</parameter>
        <parameter>(2) RECONFIGURE</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) enable/disable</technical_mechanism>
        <technical_mechanism>(2) c2 audit mode</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002426 Rule Title: C2 Audit mode should be enabled or custom audit traces defined. STIG ID: DG0510 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19784-8' platform='ms-sql2000' modified='2013-02-11'>
      <description>The SQL Mail XPs should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) EXEC SP_CONFIGURE</parameter>
        <parameter>(2) RECONFIGURE</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) enable/disable</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0003335 Rule Title: SQL Mail, SQL Mail Extended Stored Procedures (XPs) and Database Mail XPs are required and enabled. STIG ID DM0900 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19831-7' platform='ms-sql2000' modified='2013-02-11'>
      <description>The SQL Server Database Service account should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Configure the SQL Server Database Service account via the Computer Management Tool.</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) member/not member</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015170 Rule Title: SQL Server services should be assigned least privileges on the SQL Server Windows host. STIG ID: DM0919 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19935-6' platform='ms-sql2000' modified='2013-02-11'>
      <description>The SQL Server Agent account should be configured appropriately.</description>
      <parameters>
        <parameter>(1) Configure the SQL Server Agent account via the Computer Management Tool.</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) member/not member</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015170 Rule Title: SQL Server services should be assigned least privileges on the SQL Server Windows host. STIG ID: DM0919 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19971-1' platform='ms-sql2000' modified='2013-02-11'>
      <description>The SQL Server Service for a specified instance should be configure appropriately.</description>
      <parameters>
        <parameter>(1) net user &lt;username&gt; &lt;password&gt; /add</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) local account</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0003835 Rule Title: The SQL Server service should use a least-privileged local or domain user account STIG ID: DM0924 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19277-3' platform='ms-sql2000' modified='2013-02-11'>
      <description>SQL Server registry keys and sub-keys permissions should be configured appropriately.</description>
      <parameters>
        <parameter>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ MSSQLServer</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) granted/revoked</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0003838 Rule Title: SQL Server registry keys should be properly secured. STIG ID: DM0927 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19361-5' platform='ms-sql2000' modified='2013-02-11'>
      <description>Access extended stored procedure xp_cmdshell should be configured appropriately</description>
      <parameters>
        <parameter>(1) EXEC SP_CONFIGURE</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) user</technical_mechanism>
        <technical_mechanism>(2) xp_cmdshell</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002461 Rule Title: Extended stored procedure xp_cmdshell should be restricted to authorized accounts. STIG ID: DM1758 Severity: CAT I Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19930-7' platform='ms-sql2000' modified='2013-02-11'>
      <description>The xp_cmdshell should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) EXEC SP_CONFIGURE</parameter>
        <parameter>(2) RECONFIGURE</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) enabled/disabled</technical_mechanism>
        <technical_mechanism>(2)  xp_cmdshell</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002461 Rule Title: Extended stored procedure xp_cmdshell should be restricted to authorized accounts. STIG ID: DM1758 Severity: CAT I Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19289-8' platform='ms-sql2000' modified='2013-02-11'>
      <description>OLE Automation extended stored procedures should be configured appropriately.</description>
      <parameters>
        <parameter>(1) GRANT OR REVOKE  Command</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) permission</technical_mechanism>
        <technical_mechanism>(2) object name</technical_mechanism>
        <technical_mechanism>(3) user name</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID; V0002472 Rule Title: OLE Automation extended stored procedures should be restricted to sysadmin access STIG ID: DM2095 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19735-0' platform='ms-sql2000' modified='2013-02-11'>
      <description>Access to registry exended stored procedures should be configured appropriately.</description>
      <parameters>
        <parameter>From the SQL Server Management Studio GUI:</parameter>
        <parameter>1. Connect/expand SQL Server</parameter>
        <parameter>2. Expand Databases</parameter>
        <parameter>3. Expand System databases</parameter>
        <parameter>4. Expand Master</parameter>
        <parameter>5. Expand Programmability</parameter>
        <parameter>6. Expand Extended Stored Procedures</parameter>
        <parameter>7. Expand System Extended Stored Procedures</parameter>
        <parameter>8. Locate and select each of the Registry extended stored procedures listed in the Check section</parameter>
        <parameter>9. Right click on the extended stored procedure</parameter>
        <parameter>10. Select Properties</parameter>
        <parameter>11. Click on the Permissions page</parameter>
        <parameter>12. Select each user or role and select or deselect the Grant (and With Grant if checked) permissions from</parameter>
        <parameter>all users, database roles and public except from SYSADMINs and authorized roles when permitted</parameter>
        <parameter>13. Click OK</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) user/role</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002473 Rule Title: Registry extended stored procedures should be restricted to sysadmin access. STIG ID: DM2119 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19835-8' platform='ms-sql2000' modified='2013-02-11'>
      <description>Remote access should be configured appropriately</description>
      <parameters>
        <parameter>(1) EXEC SP_CONFIGURE</parameter>
        <parameter>(2) RECONFIGURE</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) remote access',</technical_mechanism>
        <technical_mechanism>(2) enabled/disabled</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002485 Rule Title: Remote access should be disabled if not authorized. STIG ID: DM2142 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19989-3' platform='ms-sql2000' modified='2013-02-11'>
      <description>SQL Server authentication should be configured appropriately.</description>
      <parameters>
        <parameter>(1) EXEC XP_LOGINCONFIG</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) 'login mode'</technical_mechanism>
        <technical_mechanism>(2) number</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002487 Rule Title: SQL Server authentication mode should be set to Windows authentication mode or Mixed mode. STIG ID: DM3566 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19398-7' platform='ms-sql2000' modified='2013-02-11'>
      <description>Access to CmdExec and ActiveScripting jobs should be configured appropriately.</description>
      <parameters>
        <parameter>(1) HKEY_LOCAL_MACHINE / SOFTWARE / MICROSOFT / MSSQLServer / SQLSERVERAGENT /  (Click on the SYSAdminOnly value)</parameter>
        <parameter>or</parameter>
        <parameter>From the SQL Server Enterprise Manager GUI:</parameter>
        <parameter>1. Connect/expand SQL Server</parameter>
        <parameter>2. Expand Management</parameter>
        <parameter>3. Right-click on SQL Server Agent</parameter>
        <parameter>4. Select Properties</parameter>
        <parameter>5. Select Job System tab</parameter>
        <parameter>6. Select or do not select the checkbox for ‘Only users with SysAdmin privileges can execute CmdExec and</parameter>
        <parameter>ActiveScripting job steps’</parameter>
        <parameter>7. Click Ok.</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>enable/disable</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002488 Rule Title: SQL Server Agent CmdExec or ActiveScripting jobs should be restricted to sysadmins. STIG ID: DM3763 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19498-5' platform='ms-sql2000' modified='2013-02-11'>
      <description>Error log retention should be configured appropriately.</description>
      <parameters>
        <parameter>(1) HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Microsoft SQL Server \ MSSQL.# \MSSQLServer \ NumErrorLogs</parameter>
        <parameter>(2) HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Microsoft SQL Server \ Instance Names \ SQL\[instance name]</parameter>
        <parameter>or</parameter>
        <parameter>From the SQL Server Management Studio GUI:</parameter>
        <parameter>1. Connect to and expand the SQL Server instance</parameter>
        <parameter>2. Expand Management</parameter>
        <parameter>3. Right-click on SQL Server Logs</parameter>
        <parameter>4. Select Configure</parameter>
        <parameter>5. Under the General Page, select or deselect Limit the number of error logs before they are</parameter>
        <parameter>recycled</parameter>
        <parameter>6. Enter the number of error log files determined for the SQL Server instance</parameter>
        <parameter>7. Click OK</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) number of error logs</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015137 Rule Title: Error log retention shoud be set to meet log retention policy. STIG ID: DM3930 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19734-3' platform='ms-sql2000' modified='2013-02-11'>
      <description>Trace rollover should be configured appropriately.</description>
      <parameters>
        <parameter>(1) EXEC SP_TRACE_CREATE [ @traceid = ] trace_id OUTPUT</parameter>
        <parameter>, [ @options = ] option_value</parameter>
        <parameter>, [ @tracefile = ] 'trace_file'</parameter>
        <parameter>[ , [ @maxfilesize = ] max_file_size ]</parameter>
        <parameter>[ , [ @stoptime = ] 'stop_time' ]</parameter>
        <parameter>[ , [ @filecount = ] 'max_rollover_files' ]</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) enable/disable</technical_mechanism>
        <technical_mechanism>(2) trace_id</technical_mechanism>
        <technical_mechanism>(3) trace_file</technical_mechanism>
        <technical_mechanism>(4) max_file_size</technical_mechanism>
        <technical_mechanism>(5) stop_time</technical_mechanism>
        <technical_mechanism>(6) max_rollover_files</technical_mechanism>
        <technical_mechanism>(2) value query (remove)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002500 Rule Title: Trace Rollover should be enabled for audit traces that have a maximum trace file size. STIG ID: DM5267 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19855-6' platform='ms-sql2000' modified='2013-02-11'>
      <description>Named Pipes network protocol should be configured appropriately.</description>
      <parameters>
        <parameter>From SQL Server Network Utility:</parameter>
        <parameter>Under Enabled protocols:</parameter>
        <parameter>1. Select Named Pipes</parameter>
        <parameter>2. Click on the appropriate option (enable or disable)</parameter>
        <parameter>3. Click OK ( to save)</parameter>
        <parameter>4. Click OK (to exit)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) enable/disable</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015124 Rule Title: The Named Pipes network protocol should be documented and approved if enabled. STIG ID: DM6015 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19788-9' platform='ms-sql2000' modified='2013-02-11'>
      <description>SQL Server event forwarding should be configured appropriately</description>
      <parameters>
        <parameter>(1) HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Microsoft SQL Sever \ MSSQL.[#] \SQLServerAgent \ AlertForwardingServer</parameter>
        <parameter>or From the SQL Server Management Studio GUI:</parameter>
        <parameter>1. Expand instance</parameter>
        <parameter>2. Right-click on SQL Server Agent</parameter>
        <parameter>3. Select Properties</parameter>
        <parameter>4. Select the Advanced page</parameter>
        <parameter>5. Click or do not click on Forward events to a different server check box</parameter>
        <parameter>6. Click the OK button to save and close</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) enable/disable</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2000 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015176 Rule Title: SQL Server event forwarding, if enabled, should be operational. STIG ID: DM6030 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19557-8' platform='ms-sql2005' modified='2013-02-11'>
      <description>Application object owner accounts for a specified database should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) login_name</parameter>
        <parameter>(2) enable/disable</parameter>
        <parameter>(3) default_database</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) ALTER LOGIN</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0005683 Rule Title: Application object owner accounts should be disabled when not performing installation or maintenance actions. STIG ID: DG0004 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19528-9' platform='ms-sql2005' modified='2013-02-11'>
      <description>Application object owner accounts for a specified database should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts</parameter>
        <parameter>(2) database name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1)From the query prompt:</technical_mechanism>
        <technical_mechanism>    USE [database name]</technical_mechanism>
        <technical_mechanism>    SELECT DISTINCT u.name</technical_mechanism>
        <technical_mechanism>    FROM sysusers u, sysobjects o</technical_mechanism>
        <technical_mechanism>    WHERE u.uid = o.uid</technical_mechanism>
        <technical_mechanism>    AND u.uid NOT IN ('1', '3', '4')</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015607 Rule Title: Application objects should be owned by accounts authorized for ownership. STIG ID: DG0008 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19358-1' platform='ms-sql2005' modified='2013-02-11'>
      <description>Database application permissions allowing DDL statements to modify the application schema for a specified database should be configured appropriately.</description>
      <parameters>
        <parameter>(1) list of permissons                                                                     </parameter>
        <parameter>(2) set of accounts</parameter>
        <parameter>(3) database name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) USE [database name]</technical_mechanism>
        <technical_mechanism>      SELECT USER_NAME(uid), name, crdate</technical_mechanism>
        <technical_mechanism>      FROM sysobjects</technical_mechanism>
        <technical_mechanism>      WHERE uid NOT IN (1, 3, 4)</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0003727 Rule Title: Database applications should be restricted from using static DDL statements to modify the application schema for a specified database. STIG ID: DG0015 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19972-9' platform='ms-sql2005' modified='2013-02-11'>
      <description>Custom and GOTS application source code for a specified databased should be encrypted or not encrypted as appropriate.</description>
      <parameters>
        <parameter>(1) [procedure name]</parameter>
        <parameter>(2) WITH ENCRYPTION</parameter>
        <parameter>(3) Custom/GOTS procedures</parameter>
        <parameter>(4) Database Name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) ALTER PROCEDURE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0003823 Rule Title: Custom and GOTS application source code stored in the database should be protected with encryption or encoding. STIG ID: DG0091 Severity: CAT III Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19571-9' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to manage the database master key for a specified database should be configured appropriately.</description>
      <parameters>
        <parameter>(1) list of users</parameter>
        <parameter>(2) database name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) REVOKE / GRANT CONTROL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015654 Rule Title: DBMS symmetric keys should be protected in accordance with NSA or NIST-approved key management technology or processes. STIG ID: DG0138 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19853-1' platform='ms-sql2005' modified='2013-02-11'>
      <description>Ownership of the asymmetric keys should be configured appropriately</description>
      <parameters>
        <parameter>(1) set of audits</parameter>
        <parameter>(2) list of permissons</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) object owners </technical_mechanism>
        <technical_mechanism>(2) defined by objects DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015142 Rule Title: Asymmetric keys should use DoD PKI Certificates and be protected in accordance with NIST (unclassified data) or NSA (classified data) approved key management and processes. STIG ID: DG0166 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19878-8' platform='ms-sql2005' modified='2013-02-11'>
      <description>Encryption of the asymmetric keys should be configured appropriately</description>
      <parameters>
        <parameter>(1) set of audits</parameter>
        <parameter>(2) list of permissons</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) object owners </technical_mechanism>
        <technical_mechanism>(2) defined by objects DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015142 Rule Title: Asymmetric keys should use DoD PKI Certificates and be protected in accordance with NIST (unclassified data) or NSA (classified data) approved key management and processes. STIG ID: DG0166 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19148-6' platform='ms-sql2005' modified='2013-02-11'>
      <description>Auditing of unauthorized access to the asymmetric keys should be configured appropriately</description>
      <parameters>
        <parameter>(1) set of audits</parameter>
        <parameter>(2) list of permissons</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) object owners </technical_mechanism>
        <technical_mechanism>(2) defined by objects DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015142 Rule Title: Asymmetric keys should use DoD PKI Certificates and be protected in accordance with NIST (unclassified data) or NSA (classified data) approved key management and processes. STIG ID: DG0166 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19173-4' platform='ms-sql2005' modified='2013-02-11'>
      <description>Permissions on system tables for a specified database should be configured appropriately</description>
      <parameters>
        <parameter>(1) list of permissons</parameter>
        <parameter>(2) [object]</parameter>
        <parameter>(3) [user name]</parameter>
        <parameter>(4) [database name]</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) REVOKE / GRANT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002458 Rule Title: Permissions on system tables should be restricted to authorized accounts. STIG ID: DM1749 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19159-3' platform='ms-sql2005' modified='2013-02-11'>
      <description>DDL permissions for a specified database and specified account should be configured appropriately</description>
      <parameters>
        <parameter>(1) set of accounts</parameter>
        <parameter>(2) list of permissions </parameter>
        <parameter>(3) database name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) CREATE</technical_mechanism>
        <technical_mechanism>(2) ALTER</technical_mechanism>
        <technical_mechanism>(3) DROP</technical_mechanism>
        <technical_mechanism>(1) REVOKE/GRANT CONTROL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002463 Rule Title: DDL permissions should be granted only to authorized accounts. STIG ID: DM1760 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19789-7' platform='ms-sql2005' modified='2013-02-11'>
      <description>Permissions using the WITH GRANT OPTION for a specified database should be configured appropriately</description>
      <parameters>
        <parameter>(1) list of permissons</parameter>
        <parameter>(2) [object]</parameter>
        <parameter>(3) [user name]</parameter>
        <parameter>(4) [database name]</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) REVOKE / GRANT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002498 Rule Title : Permissions using the WITH GRANT OPTION should be granted only to DBA or application administrator accounts. STIG ID: DM5144 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19832-5' platform='ms-sql2005' modified='2013-02-11'>
      <description>The Database Master key encryption password for a specified database should be configured appropriately</description>
      <parameters>
        <parameter>(1) &lt;regenerate option&gt; | &lt;encryption_option&gt;</parameter>
        <parameter>(2) password</parameter>
        <parameter>(3) database name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) ALTER MASTER KEY</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015159 Rule Title: The Database Master key encryption password should meet DoD password complexity requirements. STIG ID: DM6175 Severity: CAT II Class: Unclass</reference>
        <reference resource_id='Microsoft Online Documentation'>http://msdn.microsoft.com/en-us/library/ms186937(v=sql.90).aspx</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19670-9' platform='ms-sql2005' modified='2013-02-11'>
      <description>The Database Master Key for the specified database should be encrypted appropriately.</description>
      <parameters>
        <parameter>(1) encryption option</parameter>
        <parameter>(2) key option</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) ALTER MASTER KEY</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015161 Rule Title: The Database Master Key should be encrypted by the Service Master Key where required. STIG ID: DM6179 Severity: CATII Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19922-4' platform='ms-sql2005' modified='2013-02-11'>
      <description>Storage of the database master key password for a speicifed database should be configured appropriately.</description>
      <parameters>
        <parameter>(1) database name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) sp_control_dbmasterkey_password</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015162 Rule Title: Database Master Key passwords should not be stored in credentials within the database. STIG ID: DM6180 Severity: CATII Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20019-6' platform='ms-sql2005' modified='2013-02-11'>
      <description>Protection of symmetric keys for a specified database should be configured appropriately</description>
      <parameters>
        <parameter>(1) key_name </parameter>
        <parameter>(2) ENCRYPTION</parameter>
        <parameter>(3) [certificate | password | symmetric key | asymmetric key]</parameter>
        <parameter>(4) Database name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) ALTER SYMMETRIC KEY</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015168 Rule Title: Symmetric keys should use a master key, certificate, or asymmetric key to encrypt the key. STIG ID: DM6183 Severity: CATII Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19613-9' platform='ms-sql2005' modified='2013-02-11'>
      <description>Object permissions assigned to PUBLIC or GUEST for a specified database should be configured appropriately.</description>
      <parameters>
        <parameter>(1) list of permissons</parameter>
        <parameter>(2) [object]</parameter>
        <parameter>(3) [public or guest]</parameter>
        <parameter>(4) dtaabase name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) REVOKE / GRANT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 DB Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015172 Rule Title: Object permissions should not be assigned to PUBLIC or GUEST. STIG ID: DM6196</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19862-2' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to DBMS software files and directories should be configured appropriately.</description>
      <parameters>
        <parameter>(1) set of accounts </parameter>
        <parameter>(2) list of permissions</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) defined by the object's DACL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015608 Rule Title: Access to DBMS software files and directories should not be granted to unauthorized users. STIG ID: DG0009 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19872-1' platform='ms-sql2005' modified='2013-02-11'>
      <description>Default demonstration and sample database objects and applications should be available or removed as appropriate.</description>
      <parameters>
        <parameter>(1) database_name </parameter>
        <parameter>(2) database_snapshot_name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) DROP DATABASE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015609 Rule Title: Default demonstration and sample database objects and applications should be removed. STIG ID: DG0014 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19877-0' platform='ms-sql2005' modified='2013-02-11'>
      <description>Required auditing parameters for database auditing should be set appropriately</description>
      <parameters>
        <parameter>(1) TraceID</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_TRACE_SETSTATUS</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0005685 Rule Title: Required auditing parameters for database auditing should be set. STIG ID: DG0029 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19778-0' platform='ms-sql2005' modified='2013-02-11'>
      <description>DBMS privileges to restore database data or other DBMS configurations, features or objects in a specified database should be configured appropriately.</description>
      <parameters>
        <parameter>(1) database name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Use the SQL command to assign permissions to the appropriate roles</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015107 Rule Title: DBMS privileges to restore database data or other DBMS configurations, features or objects should be restricted to authorized DBMS accounts. STIG ID: DG0063 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19947-1' platform='ms-sql2005' modified='2013-02-11'>
      <description>DBMS login account password complexity requirements should be configured appropriately</description>
      <parameters>
        <parameter>(1) login name</parameter>
        <parameter>(2) on/off</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) ALTER LOGIN</technical_mechanism>
        <technical_mechanism>(2) CHECK_POLICY</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015152 Rule Title: DBMS login accounts require passwords to meet complexity requirements. STIG ID: DG0079 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19787-1' platform='ms-sql2005' modified='2013-02-11'>
      <description>DBMS settings to clear residual data from memory, data objects or files, or other storage locations should be configured appropriately.</description>
      <parameters>
        <parameter>(1) show advanced options</parameter>
        <parameter>(2) common criteria compliance enabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_CONFIGURE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015614 Rule Title: The DBMS should be configured to clear residual data from memory, data objects and files, and other storage locations. STIG ID: DG0084 Severity: CAT III Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19842-4' platform='ms-sql2005' modified='2013-02-11'>
      <description>DBMS account passwords expiration should be configured appropriately</description>
      <parameters>
        <parameter>(1) user name</parameter>
        <parameter>(2) WITH CHECK_EXPIRATION [ ON | OFF ]</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) ALTER LOGIN</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015153 Rule Title: DBMS account passwords should be set to expire every 60 days or more frequently. STIG ID: DG0125 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19439-9' platform='ms-sql2005' modified='2013-02-11'>
      <description>Passwords for DBMS default accounts should be set appropriately</description>
      <parameters>
        <parameter>(1) username</parameter>
        <parameter>(2) WITH PASSWORD [ new password ]</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) ALTER LOGIN</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015635 Rule Title: DBMS default accounts should be assigned custom passwords. STIG ID: DG0128 Severity: CAT I Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19990-1' platform='ms-sql2005' modified='2013-02-11'>
      <description>The built-in 'sa' account should be correctly named.</description>
      <parameters>
        <parameter>(1) username</parameter>
        <parameter>(2) WITH NAME = [new name]</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) ALTER LOGIN</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015638 Rule Title: DBMS default account names should be changed. STIG ID: DG0131 Severity: CAT III Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19676-6' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to the ErrorDumpDir should be audited or not audited as appropriate.</description>
      <parameters>
        <parameter>(1) audit/not audit</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL.1\CPE\ErrorDumpDir</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015643 Rule Title: Access to DBMS security should be audited. STIG ID: DG0140 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19962-0' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to the DefaultLog file should be audited or not audited as appropriate.</description>
      <parameters>
        <parameter>(1) audit/not audit</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL.1\MSSQLServer\DefaultLog</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-20011-3' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to the ErrorLogFile should be audited or not audited as appropriate.</description>
      <parameters>
        <parameter>(1) audit/not audit</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL.1\SQLServerAgent\ErrorLogFile</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-19080-1' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to the SQLPath directory should be audited or not audited as appropriate.</description>
      <parameters>
        <parameter>(1) audit/not audit</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\{INSTANCE NAME}\Setup\SQLPath</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-19817-6' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to the  BackupDirectory directory should be audited or not audited as appropriate.</description>
      <parameters>
        <parameter>(1) audit/not audit</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL.1</technical_mechanism>
        <technical_mechanism>\MSSQLServer\BackupDirectory</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-19511-5' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to the FullTextDefaultPath directory should be audited or not audited as appropriate.</description>
      <parameters>
        <parameter>(1) audit/not audit</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL.1</technical_mechanism>
        <technical_mechanism>\MSSQLServer\FullTextDefaultPath</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-19779-8' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to the WorkingDirectory directory should be audited or not audited as appropriate.</description>
      <parameters>
        <parameter>(1) audit/not audit</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL.1\Replication\WorkingDirectory</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-20001-4' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to the SQLBinRoot directory should be audited or not audited as appropriate.</description>
      <parameters>
        <parameter>(1) audit/not audit</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL.1\Setup\SQLBinRoot</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-19336-7' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to the SQLDataRoot directory should be audited or not audited as appropriate.</description>
      <parameters>
        <parameter>(1) audit/not audit</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL.1\Setup\SQLDataRoot</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-19762-4' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to the SQLPath directory should be audited or not audited as appropriate.</description>
      <parameters>
        <parameter>(1) audit/not audit</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL.1\Setup\SQLPath</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-19575-0' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to the SQLProgramDir directory should be audited or not audited as appropriate.</description>
      <parameters>
        <parameter>(1) audit/not audit</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL.1\Setup\SQLProgramDir</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-19873-9' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to the WorkingDirectory directory should be audited or not audited as appropriate.</description>
      <parameters>
        <parameter>(1) audit/not audit</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL.1\SQLServerAgent\WorkingDirectory</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-19959-6' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to the DataDir directory should be audited or not audited as appropriate.</description>
      <parameters>
        <parameter>(1) audit/not audit</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL.2\Setup\DataDir</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-19837-4' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to the SQLBinRoot directory should be audited or not audited as appropriate.</description>
      <parameters>
        <parameter>(1) audit/not audit</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL.2\Setup\SQLBinRoot</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-19748-3' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to the SQLPath directory should be audited or not audited as appropriate.</description>
      <parameters>
        <parameter>(1) audit/not audit</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1)  HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL.2\Setup\SQLPath</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-19916-6' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to the SQLProgramDir directory should be audited or not audited as appropriate.</description>
      <parameters>
        <parameter>(1) audit/not audit</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1)  HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL.2\Setup\SQLProgramDir</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-19827-5' platform='ms-sql2005' modified='2013-02-11'>
      <description>Auditing attempts to bypass access controls should be configured appropriately.</description>
      <parameters>
        <parameter>(1) on/off</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC XP_LOGINCONFIG</technical_mechanism>
        <technical_mechanism>From the SQL Server Management Studio GUI:</technical_mechanism>
        <technical_mechanism>1. Navigate to the SQL Server instance name</technical_mechanism>
        <technical_mechanism>2. Right-click on it</technical_mechanism>
        <technical_mechanism>3. Select Properties</technical_mechanism>
        <technical_mechanism>4. Select Security tab or page</technical_mechanism>
        <technical_mechanism>5. Review Login Auditing selection</technical_mechanism>
        <technical_mechanism>6. Select "Failed logins only" or "Both failed and successful logins" from the Login Auditing section</technical_mechanism>
        <technical_mechanism>7. Apply changes</technical_mechanism>
        <technical_mechanism>8. Exit the SQL Server Management Studio GUI</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015644 Rule Title: Attempts to bypass access controls should be audited. STIG ID: DG0141 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19950-5' platform='ms-sql2005' modified='2013-02-11'>
      <description>The default audit trace option should be configured appropriately.</description>
      <parameters>
        <parameter>(1) show advanced options</parameter>
        <parameter>(2) default trace enabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_CONFIGURE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015645 Rule Title: Changes to configuration options should be audited. STIG ID: DG0142 Severity CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19813-5' platform='ms-sql2005' modified='2013-02-11'>
      <description>Audit records contents should be configured appropriately.</description>
      <parameters>
        <parameter>(1) @traceid</parameter>
        <parameter>(2) @eventid</parameter>
        <parameter>(3) @columnid</parameter>
        <parameter>(4) @on</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_TRACE_SETEVENT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015646 Rule Title: Audit records should contain required information. STIG ID: DG0145 Severity: CAT II Class: Unclass</reference>
        <reference resource_id='Microsoft Online Documentation'>http://msdn.microsoft.com/en-us/library/ms186265(v=sql.90).aspx</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19741-8' platform='ms-sql2005' modified='2013-02-11'>
      <description>The port which Sql Server Analysis Services uses should be configured appropriately.</description>
      <parameters>
        <parameter>(1) [ 0 | port number ]</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Sql Server Management Studio GUI \ Analysis Services Instance</technical_mechanism>
        <technical_mechanism>From the SQL Server Management Studio GUI:</technical_mechanism>
        <technical_mechanism>1. Connect to the Analysis Services instance</technical_mechanism>
        <technical_mechanism>2. Right click on the Analysis Services instance</technical_mechanism>
        <technical_mechanism>3. Select Properties</technical_mechanism>
        <technical_mechanism>4. View the value listed for Port</technical_mechanism>
        <technical_mechanism>5. Set value to IAO-approved value</technical_mechanism>
        <technical_mechanism>6. Click OK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015648 Rule Title: Access to the DBMS should be restricted to static, default network ports. STIG ID: DG0151 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19891-1' platform='ms-sql2005' modified='2013-02-11'>
      <description>The ports which the DBMS uses should be configured appropriately.</description>
      <parameters>
        <parameter>(1) [ 0 | port number ]</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Microsoft SQL Server \ MSSQL.[#] \</technical_mechanism>
        <technical_mechanism>MSSQLServer \ SuperSocketNetLib \ IPAll \ TCPDynamicPorts</technical_mechanism>
        <technical_mechanism>(2) HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Microsoft SQL Server \ MSSQL.[#] \</technical_mechanism>
        <technical_mechanism>MSSQLServer \ SuperSocketNetLib \ IPAll \ TcpPort</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015148 Rule Title: DBMS network communications should comply with PPS usage restrictions. STIG ID: DG0152 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19453-0' platform='ms-sql2005' modified='2013-02-11'>
      <description>Remote DBMS administration should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) remote admin connections</parameter>
        <parameter>(2) enable/disable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_CONFIGURE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015651 Rule Title: Remote DBMS administration should be documented and authorized or disabled. STIG ID: DG0157 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19727-7' platform='ms-sql2005' modified='2013-02-11'>
      <description>Fixed server roll membership should be configured appropriately.</description>
      <parameters>
        <parameter>(1) @loginname</parameter>
        <parameter>(2) @rolename</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) SP_DROPSRVROLEMEMBER</technical_mechanism>
        <technical_mechanism>(2) SP_ADDSRVROLEMEMBER</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002427 Rule Title: Fixed Server roles should have only authorized users or groups assigned as members STIG ID: DG0510 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19808-5' platform='ms-sql2005' modified='2013-02-11'>
      <description>C2 Audit records should be configured appropriately</description>
      <parameters>
        <parameter>(1) enable/disable</parameter>
        <parameter>(2) c2 audit mode</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_CONFIGURE</technical_mechanism>
        <technical_mechanism>(2) RECONFIGURE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002426 Rule Title: C2 Audit mode should be enabled or custom audit traces defined. STIG ID: DG0510 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19866-3' platform='ms-sql2005' modified='2013-02-11'>
      <description>The SQL Mail XPs should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enable/disable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_CONFIGURE</technical_mechanism>
        <technical_mechanism>(2) RECONFIGURE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0003335 Rule Title: SQL Mail, SQL Mail Extended Stored Procedures (XPs) and Database Mail XPs are required and enabled. STIG ID DM0900 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19577-6' platform='ms-sql2005' modified='2013-02-11'>
      <description>The Database Mail XPs should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enable/disable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_CONFIGURE</technical_mechanism>
        <technical_mechanism>(2) RECONFIGURE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0003335 Rule Title: SQL Mail, SQL Mail Extended Stored Procedures (XPs) and Database Mail XPs are required and enabled. STIG ID DM0900 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19785-5' platform='ms-sql2005' modified='2013-02-11'>
      <description>SQL Server Agent Email should be configured appropriately</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>From the SQL Server Management Studio GUI:</technical_mechanism>
        <technical_mechanism>1. Right click on SQL Server Agent</technical_mechanism>
        <technical_mechanism>2. Select Properties</technical_mechanism>
        <technical_mechanism>3. Select Alert System</technical_mechanism>
        <technical_mechanism>4. Check or uncheck the "Enable Mail profile.</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0003336 Rule Title: SQL Server Agent email notification usage if enabled should be documented and approved by the IAO. STIG ID: DM0901 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19640-2' platform='ms-sql2005' modified='2013-02-11'>
      <description>The SQL Server Database Service account should be configured appropriately.</description>
      <parameters>
        <parameter>(1) member/not member</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Configure the SQL Server Database Service account via the Computer Management Tool.</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015170 Rule Title: SQL Server services should be assigned least privileges on the SQL Server Windows host. STIG ID: DM0919 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19879-6' platform='ms-sql2005' modified='2013-02-11'>
      <description>The SQL Server Agent account should be configured appropriately.</description>
      <parameters>
        <parameter>(1) member/not member</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Configure the SQL Server Agent Service account via the Computer Management Tool.</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015170 Rule Title: SQL Server services should be assigned least privileges on the SQL Server Windows host. STIG ID: DM0919 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19560-2' platform='ms-sql2005' modified='2013-02-11'>
      <description>The Analysis Services account should be configured appropriately.</description>
      <parameters>
        <parameter>(1) member/not member</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Configure the Analysis Services account via the Computer Management Tool.</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015170 Rule Title: SQL Server services should be assigned least privileges on the SQL Server Windows host. STIG ID: DM0919 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19703-8' platform='ms-sql2005' modified='2013-02-11'>
      <description>The Integration Services account should be configured appropriately.</description>
      <parameters>
        <parameter>(1) member/not member</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Configure the Integration Services account via the Computer Management Tool.</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015170 Rule Title: SQL Server services should be assigned least privileges on the SQL Server Windows host. STIG ID: DM0919 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19802-8' platform='ms-sql2005' modified='2013-02-11'>
      <description>The Reporting Services account should be configured appropriately.</description>
      <parameters>
        <parameter>(1) member/not member</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Configure the Reporting Services account via the Computer Management Tool.</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015170 Rule Title: SQL Server services should be assigned least privileges on the SQL Server Windows host. STIG ID: DM0919 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20033-7' platform='ms-sql2005' modified='2013-02-11'>
      <description>The Notification Services account should be configured appropriately.</description>
      <parameters>
        <parameter>(1) member/not member</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Configure the Notification Services account via the Computer Management Tool.</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015170 Rule Title: SQL Server services should be assigned least privileges on the SQL Server Windows host. STIG ID: DM0919 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19418-3' platform='ms-sql2005' modified='2013-02-11'>
      <description>The Full Text Search account should be configured appropriately.</description>
      <parameters>
        <parameter>(1) member/not member</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Configure the Full Text Search account via the Computer Management Tool.</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015170 Rule Title: SQL Server services should be assigned least privileges on the SQL Server Windows host. STIG ID: DM0919 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19318-5' platform='ms-sql2005' modified='2013-02-11'>
      <description>The SQL Server Browser account should be configured appropriately.</description>
      <parameters>
        <parameter>(1) member/not member</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Configure the SQL Server Browser account via the Computer Management Tool.</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015170 Rule Title: SQL Server services should be assigned least privileges on the SQL Server Windows host. STIG ID: DM0919 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19302-9' platform='ms-sql2005' modified='2013-02-11'>
      <description>The SQL Server Active Directory Helper account should be configured appropriately.</description>
      <parameters>
        <parameter>(1) member/not member</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Configure the SQL Server Active Directory Helper account via the Computer Management Tool.</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015170 Rule Title: SQL Server services should be assigned least privileges on the SQL Server Windows host. STIG ID: DM0919 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19923-2' platform='ms-sql2005' modified='2013-02-11'>
      <description>The SQL Writer account should be configured appropriately.</description>
      <parameters>
        <parameter>(1) member/not member</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Configure the SQL Writer account via the Computer Management Tool.</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015170 Rule Title: SQL Server services should be assigned least privileges on the SQL Server Windows host. STIG ID: DM0919 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19738-4' platform='ms-sql2005' modified='2013-02-11'>
      <description>The SQL Server Service for a specified instance should be configure appropriately.</description>
      <parameters>
        <parameter>(1) local account</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) net user &lt;username&gt; &lt;password&gt; /add</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0003835 Rule Title: The SQL Server service should use a least-privileged local or domain user account STIG ID: DM0924 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19852-3' platform='ms-sql2005' modified='2013-02-11'>
      <description>The SQLServer2005ReportServerUser registry key permissions should be configured appropriately.</description>
      <parameters>
        <parameter>(1) granted/revoked</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Microsoft SQL Server \ Instance Names \RS \SQLServer2005ReportServerUser$[instancename]</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0003838 Rule Title: SQL Server registry keys should be properly secured. STIG ID: DM0927 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19494-4' platform='ms-sql2005' modified='2013-02-11'>
      <description>The SQL Server MSSearch registry key permissions should be configured appropriately.</description>
      <parameters>
        <parameter>(1) granted/revoked</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Microsoft SQL Server \ MSSQL.1 \MSSearch \</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0003838 Rule Title: SQL Server registry keys should be properly secured. STIG ID: DM0927 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19254-2' platform='ms-sql2005' modified='2013-02-11'>
      <description>The SQL Server Agent registry key permissions should be configured appropriately.</description>
      <parameters>
        <parameter>(1) granted/revoked</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Microsoft SQL Server \ MSSQL.1 \SQLServerAgent \</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0003838 Rule Title: SQL Server registry keys should be properly secured. STIG ID: DM0927 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19325-0' platform='ms-sql2005' modified='2013-02-11'>
      <description>The SQLServerADHelperUser registry key permissions should be configured appropriately.</description>
      <parameters>
        <parameter>(1) granted/revoked</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Microsoft SQL Server \ MSSQL.1\SQLServerAgent\SQLServer2005SQLServerADHelperUser$[instance name]</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0003838 Rule Title: SQL Server registry keys should be properly secured. STIG ID: DM0927 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19776-4' platform='ms-sql2005' modified='2013-02-11'>
      <description>The SQL Server RS registry key permissions should be configured appropriately.</description>
      <parameters>
        <parameter>(1) granted/revoked</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Microsoft SQL Server \ Instance Names \RS \</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0003838 Rule Title: SQL Server registry keys should be properly secured. STIG ID: DM0927 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19356-5' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access extended stored procedure xp_cmdshell should be configured appropriately</description>
      <parameters>
        <parameter>(1) user</parameter>
        <parameter>(2) xp_cmdshell</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_CONFIGURE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002461 Rule Title: Extended stored procedure xp_cmdshell should be restricted to authorized accounts. STIG ID: DM1758 Severity: CAT I Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19896-0' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access extended stored procedure xp_cmdshell should be configured appropriately</description>
      <parameters>
        <parameter>(1) revoke/grant</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(2) REVOKE / GRANT EXECUTE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002461 Rule Title: Extended stored procedure xp_cmdshell should be restricted to authorized accounts. STIG ID: DM1758 Severity: CAT I Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19967-9' platform='ms-sql2005' modified='2013-02-11'>
      <description>The xp_cmdshell should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
        <parameter>(2)  xp_cmdshell</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_CONFIGURE</technical_mechanism>
        <technical_mechanism>(2) RECONFIGURE</technical_mechanism>
      </technical_mechanisms>
      <references />
    </cce>
    <cce cce_id='CCE-19976-0' platform='ms-sql2005' modified='2013-02-11'>
      <description>The "scan for startup procs" setting should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) 'scan for startup procs' </parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_CONFIGURE </technical_mechanism>
        <technical_mechanism>(2) RECONFIGURE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002464 Rule Title: Execute stored procedures at startup, if enabled, should have a custom audit trace defined. STIG ID: DM1761 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19172-6' platform='ms-sql2005' modified='2013-02-11'>
      <description>OLE Automation extended stored procedures should configured appropriately.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_CONFIGURE</technical_mechanism>
        <technical_mechanism>(2) RECONFIGURE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID; V0002472 Rule Title: OLE Automation extended stored procedures should be restricted to sysadmin access STIG ID: DM2095 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20018-8' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to registry exended stored procedures should be configured appropriately.</description>
      <parameters>
        <parameter>(1) user/role</parameter>
        <parameter>(2) Grant/Revoke</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>From the SQL Server Management Studio GUI:</technical_mechanism>
        <technical_mechanism>1. Connect/expand SQL Server</technical_mechanism>
        <technical_mechanism>2. Expand Databases</technical_mechanism>
        <technical_mechanism>3. Expand System databases</technical_mechanism>
        <technical_mechanism>4. Expand Master</technical_mechanism>
        <technical_mechanism>5. Expand Programmability</technical_mechanism>
        <technical_mechanism>6. Expand Extended Stored Procedures</technical_mechanism>
        <technical_mechanism>7. Expand System Extended Stored Procedures</technical_mechanism>
        <technical_mechanism>8. Locate and select each of the Registry extended stored procedures listed in the Check section</technical_mechanism>
        <technical_mechanism>9. Right click on the extended stored procedure</technical_mechanism>
        <technical_mechanism>10. Select Properties</technical_mechanism>
        <technical_mechanism>11. Click on the Permissions page</technical_mechanism>
        <technical_mechanism>12. Select each user or role and select or deselect the Grant (and With Grant if checked) permissions from</technical_mechanism>
        <technical_mechanism>all users, database roles and public except from SYSADMINs and authorized roles when permitted</technical_mechanism>
        <technical_mechanism>13. Click OK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002473 Rule Title: Registry extended stored procedures should be restricted to sysadmin access. STIG ID: DM2119 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19786-3' platform='ms-sql2005' modified='2013-02-11'>
      <description>Remote access should be configured appropriately</description>
      <parameters>
        <parameter>(1) remote access',</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_CONFIGURE</technical_mechanism>
        <technical_mechanism>(2) RECONFIGURE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002485 Rule Title: Remote access should be disabled if not authorized. STIG ID: DM2142 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19936-4' platform='ms-sql2005' modified='2013-02-11'>
      <description>SQL Server authentication should be configured appropriately.</description>
      <parameters>
        <parameter>(1) 'login mode'</parameter>
        <parameter>(2) number</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC XP_LOGINCONFIG</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002487 Rule Title: SQL Server authentication mode should be set to Windows authentication mode or Mixed mode. STIG ID: DM3566 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19839-0' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to SQL Server Agent CmdExec should be configured appropriately.</description>
      <parameters>
        <parameter>(1) '[login name]'</parameter>
        <parameter>(2) @proxy_name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_REVOKE_LOGIN_FROM_PROXY</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002488 Rule Title: SQL Server Agent CmdExec or ActiveScripting jobs should be restricted to sysadmins. STIG ID: DM3763 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19320-1' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to ActiveScripting jobs should be configured appropriately.</description>
      <parameters>
        <parameter>(1) '[login name]'</parameter>
        <parameter>(2) @proxy_name</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_REVOKE_LOGIN_FROM_PROXY</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002488 Rule Title: SQL Server Agent CmdExec or ActiveScripting jobs should be restricted to sysadmins. STIG ID: DM3763 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19771-5' platform='ms-sql2005' modified='2013-02-11'>
      <description>Error log retention should be configured appropriately.</description>
      <parameters>
        <parameter>(1) number of error logs</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Microsoft SQL Server \ MSSQL.# \MSSQLServer \ NumErrorLogs</technical_mechanism>
        <technical_mechanism>(2) HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Microsoft SQL Server \ Instance Names \ SQL\[instance name]</technical_mechanism>
        <technical_mechanism>or</technical_mechanism>
        <technical_mechanism>From the SQL Server Management Studio GUI:</technical_mechanism>
        <technical_mechanism>1. Connect to and expand the SQL Server instance</technical_mechanism>
        <technical_mechanism>2. Expand Management</technical_mechanism>
        <technical_mechanism>3. Right-click on SQL Server Logs</technical_mechanism>
        <technical_mechanism>4. Select Configure</technical_mechanism>
        <technical_mechanism>5. Under the General Page, select or deselect Limit the number of error logs before they are</technical_mechanism>
        <technical_mechanism>recycled</technical_mechanism>
        <technical_mechanism>6. Enter the number of error log files determined for the SQL Server instance</technical_mechanism>
        <technical_mechanism>7. Click OK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015137 Rule Title: Error log retention shoud be set to meet log retention policy. STIG ID: DM3930 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19237-7' platform='ms-sql2005' modified='2013-02-11'>
      <description>Trace rollover should be configured appropriately.</description>
      <parameters>
        <parameter>(1) enable/disable</parameter>
        <parameter>(2) trace_id</parameter>
        <parameter>(3) trace_file</parameter>
        <parameter>(4) max_file_size</parameter>
        <parameter>(5) stop_time</parameter>
        <parameter>(6) max_rollover_files</parameter>
        <parameter>(2) value query (remove)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_TRACE_CREATE [ @traceid = ] trace_id OUTPUT</technical_mechanism>
        <technical_mechanism>, [ @options = ] option_value</technical_mechanism>
        <technical_mechanism>, [ @tracefile = ] 'trace_file'</technical_mechanism>
        <technical_mechanism>[ , [ @maxfilesize = ] max_file_size ]</technical_mechanism>
        <technical_mechanism>[ , [ @stoptime = ] 'stop_time' ]</technical_mechanism>
        <technical_mechanism>[ , [ @filecount = ] 'max_rollover_files' ]</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0002500 Rule Title: Trace Rollover should be enabled for audit traces that have a maximum trace file size. STIG ID: DM5267 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19244-3' platform='ms-sql2005' modified='2013-02-11'>
      <description>Named Pipes network protocol should be configured appropriately.</description>
      <parameters>
        <parameter>(1) enable/disable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>From the SQL Server Configuration Manager GUI:</technical_mechanism>
        <technical_mechanism>1. Expand SQL Server 2005 Network Configuration</technical_mechanism>
        <technical_mechanism>2. Repeat for each instance:</technical_mechanism>
        <technical_mechanism>a. Select Protocols for [instance name]</technical_mechanism>
        <technical_mechanism>b. Double-click Named Pipes.</technical_mechanism>
        <technical_mechanism>c. Select Yes or No as the value.</technical_mechanism>
        <technical_mechanism>d. Click OK</technical_mechanism>
        <technical_mechanism>3. Click OK (acknowledge change won't take place until next restart)</technical_mechanism>
        <technical_mechanism>4. Exit the SQL Server Configuration Manager GUI</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015124 Rule Title: The Named Pipes network protocol should be documented and approved if enabled. STIG ID: DM6015 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20000-6' platform='ms-sql2005' modified='2013-02-11'>
      <description>SQL Server event forwarding should be configured appropriately</description>
      <parameters>
        <parameter>(1) enable/disable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Microsoft SQL Sever \ MSSQL.[#] \SQLServerAgent \ AlertForwardingServer</technical_mechanism>
        <technical_mechanism>or From the SQL Server Management Studio GUI:</technical_mechanism>
        <technical_mechanism>1. Expand instance</technical_mechanism>
        <technical_mechanism>2. Right-click on SQL Server Agent</technical_mechanism>
        <technical_mechanism>3. Select Properties</technical_mechanism>
        <technical_mechanism>4. Select the Advanced page</technical_mechanism>
        <technical_mechanism>5. Click or do not click on Forward events to a different server check box</technical_mechanism>
        <technical_mechanism>6. Click the OK button to save and close</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015176 Rule Title: SQL Server event forwarding, if enabled, should be operational. STIG ID: DM6030 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19744-2' platform='ms-sql2005' modified='2013-02-11'>
      <description>SQL Server Agent proxies should be configured appropriately.</description>
      <parameters>
        <parameter>(1) '[proxy name]'</parameter>
        <parameter>(2) set of permissons</parameter>
        <parameter>(3) group of users</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) SP_ENUM_PROXY_FOR_SUBSYSTEM</technical_mechanism>
        <technical_mechanism>(2) EXEC SP_REVOKE_LOGIN_FROM_PROXY</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015125 Rule Title: Only authorized users should be assigned permissions to SQL Server Agent proxies. STIG ID: DM6045 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19561-0' platform='ms-sql2005' modified='2013-02-11'>
      <description>Replication snapshot folders should be configured appropriately.</description>
      <parameters>
        <parameter>(1) list of permissions/roles</parameter>
        <parameter>(2) group of accounts</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>From Windows Explorer:</technical_mechanism>
        <technical_mechanism>1. Administrators/DBAs: assign appropriate permission</technical_mechanism>
        <technical_mechanism>2. Snapshot Agents: assign appropriate permission</technical_mechanism>
        <technical_mechanism>3. Merge, Subscription, and Distribution agents: assign appropriate permission</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015182 Rule Title: Replication snapshot folders should be protected from unauthorized access. STIG ID: DM6075 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19897-8' platform='ms-sql2005' modified='2013-02-11'>
      <description>Ad hoc data mining queries configuration option should be configured appropriately</description>
      <parameters>
        <parameter>(1) enable/disable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) The configuration file (msmdsrv.ini) may be found in the [install dir] \ MSSQL.[#] \ OLAP \ Config directory.</technical_mechanism>
        <technical_mechanism>(2) AllowAdHocOpenRowsetQueries </technical_mechanism>
        <technical_mechanism>or</technical_mechanism>
        <technical_mechanism>From the SQL Server 2005 Surface Area Configuration GUI:</technical_mechanism>
        <technical_mechanism>1. Click on Surface Area config for features</technical_mechanism>
        <technical_mechanism>2. Expand Analysis Services</technical_mechanism>
        <technical_mechanism>3. Select Ad Hoc Data Mining Queries</technical_mechanism>
        <technical_mechanism>4. Enable or disable as necessary</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015183 Rule Title: The Analysis Services ad hoc data mining queries configuration option should be disabled if not required. STIG ID: DM6085 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19298-9' platform='ms-sql2005' modified='2013-02-11'>
      <description>Analysis Services Anonymous Connections should be configured appropriately</description>
      <parameters>
        <parameter>(1) enable/disable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) The configuration file (msmdsrv.ini) may be found in the [install dir] \ MSSQL.[#] \ OLAP \ Config directory.</technical_mechanism>
        <technical_mechanism>(2) RequireClientAuthentication or</technical_mechanism>
        <technical_mechanism>From the SQL Server Management Studio GUI:</technical_mechanism>
        <technical_mechanism>1. Connect to the Analysis Services instance</technical_mechanism>
        <technical_mechanism>2. Right click on the Analysis Services instance</technical_mechanism>
        <technical_mechanism>3. Select Properties</technical_mechanism>
        <technical_mechanism>4. View the value listed for Security \ RequireClientAuthentication</technical_mechanism>
        <technical_mechanism>5. Select value = 'true or false'</technical_mechanism>
        <technical_mechanism>6. Click OK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015184 Rule Title: Analysis Services Anonymous Connections should be disabled. STIG ID: DM6086 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-20032-9' platform='ms-sql2005' modified='2013-02-11'>
      <description>Analysis Services Links to Objects is should be configured appropriately</description>
      <parameters>
        <parameter>(1) enable/disable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) The configuration file (msmdsrv.ini) may be found in the [install dir] \ MSSQL.[#] \ OLAP \ Config directory.</technical_mechanism>
        <technical_mechanism>(2) LinkToOtherInstanceEnabled or</technical_mechanism>
        <technical_mechanism>From the SQL Server Management Studio GUI:</technical_mechanism>
        <technical_mechanism>1. Connect to the Analysis Services instance</technical_mechanism>
        <technical_mechanism>2. Right click on the Analysis Services instance</technical_mechanism>
        <technical_mechanism>3. Select Properties</technical_mechanism>
        <technical_mechanism>4. View the value listed for Feature \ LinkToOtherInstanceEnabled</technical_mechanism>
        <technical_mechanism>5. Select value = 'true or false'</technical_mechanism>
        <technical_mechanism>6. Click OK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015204 Rule Title: Analysis Services Links to Objects should be disabled if not required. STIG ID: DM6087 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19964-6' platform='ms-sql2005' modified='2013-02-11'>
      <description>Analysis Services Links From Objects should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enable/disable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) The configuration file (msmdsrv.ini) may be found in the [install dir] \ MSSQL.[#] \ OLAP \ Config directory.</technical_mechanism>
        <technical_mechanism>(2) LinkFromOtherInstanceEnabled or</technical_mechanism>
        <technical_mechanism>From the SQL Server Management Studio GUI:</technical_mechanism>
        <technical_mechanism>1. Connect to the Analysis Services instance</technical_mechanism>
        <technical_mechanism>2. Right click on the Analysis Services instance</technical_mechanism>
        <technical_mechanism>3. Select Properties</technical_mechanism>
        <technical_mechanism>4. View the value listed for Feature \ LinkFromOtherInstanceEnabled</technical_mechanism>
        <technical_mechanism>5. Select value = 'true or false'</technical_mechanism>
        <technical_mechanism>6. Click Ok.</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015186 Rule Title: Analysis Services Links From Objects should be disabled if not required STIG ID: DM 6088 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19664-2' platform='ms-sql2005' modified='2013-02-11'>
      <description>Analysis Services user-defined COM functions should be configured appropriately</description>
      <parameters>
        <parameter>(1) enable/disable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) The configuration file (msmdsrv.ini) may be found in the [install dir] \ MSSQL.[#] \ OLAP \ Config directory.</technical_mechanism>
        <technical_mechanism>(2) ComUdfEnabled or</technical_mechanism>
        <technical_mechanism>From the SQL Server Management Studio GUI:</technical_mechanism>
        <technical_mechanism>1. Connect to the Analysis Services instance</technical_mechanism>
        <technical_mechanism>2. Right click on the Analysis Services instance</technical_mechanism>
        <technical_mechanism>3. Select Properties</technical_mechanism>
        <technical_mechanism>4. View the value listed for Feature \ ComUdfEnabled</technical_mechanism>
        <technical_mechanism>5. Select value = 'true or false'</technical_mechanism>
        <technical_mechanism>6. Click OK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015181 Rule Title: Analysis Services user-defined COM functions should be disabled if not required. STIG ID: DM6099 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19859-8' platform='ms-sql2005' modified='2013-02-11'>
      <description>Analysis Services Required Protection Levels should be configured appropriately</description>
      <parameters>
        <parameter>(1) tag level values</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) msmdsrv.ini</technical_mechanism>
        <technical_mechanism>(2) HKLM\SOFTWARE\Microsoft\Microsoft SQL Server\MSSQL.1\Setup\SqlProgramDir</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015188 Rule Title: Analysis Services Required Protection Level should be set to 1. STIG ID: DM6101 Severity: CAT I Class:Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19876-2' platform='ms-sql2005' modified='2013-02-11'>
      <description>Analysis Services Security Package List should be configured appropriately</description>
      <parameters>
        <parameter>(1) list of packages</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) msmdsrv.ini</technical_mechanism>
        <technical_mechanism>(2) [install dir] \ MSSQL.[#] \ OLAP \ Config directory.</technical_mechanism>
        <technical_mechanism>From the SQL Server Management Studio GUI:</technical_mechanism>
        <technical_mechanism>1. Connect to the Analysis Services instance</technical_mechanism>
        <technical_mechanism>2. Right click on the Analysis Services instance</technical_mechanism>
        <technical_mechanism>3. Select Properties</technical_mechanism>
        <technical_mechanism>4. View the value listed for Security \ SecurityPackageList</technical_mechanism>
        <technical_mechanism>5. Select value and delete or do not delete all unauthorized packages from the list</technical_mechanism>
        <technical_mechanism>6. Click OK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015190 Rule Title: Analysis Services Security Package List should be disabled if not required. STIG ID: DM6103 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19858-0' platform='ms-sql2005' modified='2013-02-11'>
      <description>The Analysis Services server role should be configured appropriately</description>
      <parameters>
        <parameter>(1) usernames</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>From the SQL Server Management Studio GUI:</technical_mechanism>
        <technical_mechanism>1. Connect to the Analysis Services instance</technical_mechanism>
        <technical_mechanism>2. Right click on the Analysis Services instance</technical_mechanism>
        <technical_mechanism>3. Select Properties</technical_mechanism>
        <technical_mechanism>4. Select the Security page</technical_mechanism>
        <technical_mechanism>5. Select any unauthorized user to remove</technical_mechanism>
        <technical_mechanism>6. Click or do not click the Remove button</technical_mechanism>
        <technical_mechanism>7. Click OK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015193 Rule Title: The Analysis Services server role should be restricted to authorized users. STIG ID: DM6108 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19974-5' platform='ms-sql2005' modified='2013-02-11'>
      <description>Analysis Services database roles should be configured appropriately for a specified server.</description>
      <parameters>
        <parameter>(1) database name</parameter>
        <parameter>(2) database roles</parameter>
        <parameter>(3) usernames</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>From the SQL Server Management Studio GUI:</technical_mechanism>
        <technical_mechanism>1. Connect to the Analysis Services instance</technical_mechanism>
        <technical_mechanism>2. Expand the Analysis Services instance</technical_mechanism>
        <technical_mechanism>3. Expand Databases</technical_mechanism>
        <technical_mechanism>4. Repeat for each database:</technical_mechanism>
        <technical_mechanism>a. Click on each database role</technical_mechanism>
        <technical_mechanism>b. Open the member list</technical_mechanism>
        <technical_mechanism>c. Select any unauthorized users</technical_mechanism>
        <technical_mechanism>d. Click or unclick the Remove button</technical_mechanism>
        <technical_mechanism>e. Click OK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015194 Rule Title: Only authorized accounts should be assigned to one or more Analysis Services database roles. STIG ID: DM6109 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19800-2' platform='ms-sql2005' modified='2013-02-11'>
      <description>Reporting Services Web service requests and HTTP should be configured appropriately</description>
      <parameters>
        <parameter>(1) enable/disable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>From Surface Area Configuration for Features:</technical_mechanism>
        <technical_mechanism>1. Connect to the Report Services instance</technical_mechanism>
        <technical_mechanism>2. Expand the instance</technical_mechanism>
        <technical_mechanism>3. Expand Report Services</technical_mechanism>
        <technical_mechanism>4. Select Web Service Requests and HTTP Access</technical_mechanism>
        <technical_mechanism>5. Click on or do not click on Enable Web Service Requests and HTTP access check box</technical_mechanism>
        <technical_mechanism>6. Click OK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015199 Rule Title: Reporting Services Web service requests and HTTP access should be disabled if not required. STIG ID: DM6120 Severity: CAT III Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19844-0' platform='ms-sql2005' modified='2013-02-11'>
      <description>Reporting Services scheduled events and report delivery should be enabled or disabled as appropriate.</description>
      <parameters>
        <parameter>(1) enable/disable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>From Surface Area Configuration for Features:</technical_mechanism>
        <technical_mechanism>1. Connect to the Report Services instance</technical_mechanism>
        <technical_mechanism>2. Expand the instance</technical_mechanism>
        <technical_mechanism>3. Expand Report Services</technical_mechanism>
        <technical_mechanism>4. Select Scheduled events and report delivery</technical_mechanism>
        <technical_mechanism>5. Click or do not click on the Scheduled events and report delivery check box</technical_mechanism>
        <technical_mechanism>6. Click OK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015205 Rule Title: Reporting Services scheduled events and report delivery should be disabled if not required. STIG ID: DM6121 Severity: CAT III Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19662-6' platform='ms-sql2005' modified='2013-02-11'>
      <description>Reporting Services Windows Integrated Security accounts should be configured appropriately</description>
      <parameters>
        <parameter>(1) enable/disable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>From Surface Area Configuration for Features:</technical_mechanism>
        <technical_mechanism>1. Connect to the Report Services instance</technical_mechanism>
        <technical_mechanism>2. Expand the instance</technical_mechanism>
        <technical_mechanism>3. Expand Report Services</technical_mechanism>
        <technical_mechanism>4. Select Windows Integrated Security</technical_mechanism>
        <technical_mechanism>5. Click on or do not click on Windows Integrated Security  check box</technical_mechanism>
        <technical_mechanism>6. Click OK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015203 Rule Title: Reporting Services Windows Integrated Security should be disabled. STIG ID: DM6122 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19756-6' platform='ms-sql2005' modified='2013-02-11'>
      <description>Command Language Runtime objects should be configured appropriately</description>
      <parameters>
        <parameter>(1) enable/disable</parameter>
        <parameter>(3) clr_enabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_CONFIGURE</technical_mechanism>
        <technical_mechanism>(2) RECONFIGURE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015202 Rule Title: Use of Command Language Runtime objects should be disabled if not required. STIG ID: DM6123 Severity: CAT III Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19893-7' platform='ms-sql2005' modified='2013-02-11'>
      <description>XML Web Services endpoints should be configured appropriately</description>
      <parameters>
        <parameter>(1) enable/disable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) CREATE / DROP ENDPOINT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015206 Rule Title: Only authorized XML Web Service endpoints should be configured on the server STIG ID: DM6126 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19484-5' platform='ms-sql2005' modified='2013-02-11'>
      <description>The db_owner role members for a specified replication database should be configured appropriately.</description>
      <parameters>
        <parameter>(1)  database_name</parameter>
        <parameter>(2) db_owner'</parameter>
        <parameter>(3) '[account name]'</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_DROPROLEMEMBER</technical_mechanism>
        <technical_mechanism>(2) EXEC SP_ADDROLEMEMBER</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015178 Rule Title: Replication databases should have authorized db_owner role members. The replication monitor role should have authorized members. STIG ID: DM6070 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19965-3' platform='ms-sql2005' modified='2013-02-11'>
      <description>The Web Assistant procedures configuration option should be configured appropriately</description>
      <parameters>
        <parameter>(1) enable/disable</parameter>
        <parameter>(2) 'Web Assistant procedures'</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_CONFIGURE</technical_mechanism>
        <technical_mechanism>(2) RECONFIGURE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015198 Rule Title: The Web Assistant procedures configuration option should be disabled if not required. STIG ID: DM6130 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19868-9' platform='ms-sql2005' modified='2013-02-11'>
      <description>The permissions of the SQL Server Agent proxy accounts should be configured appropriately.</description>
      <parameters>
        <parameter>(1) account creation</parameter>
        <parameter>(2) list of priveleges</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) server agent proxies</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015197 Rule Title: Dedicated accounts should be designated for SQL Server Agent proxies. STIG ID: DM6140 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19805-1' platform='ms-sql2005' modified='2013-02-11'>
      <description>"Disallow adhoc access" for linked servers should be configured appropriately</description>
      <parameters>
        <parameter>(1) enable/disable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>From the SQL Server Management Studio GUI:</technical_mechanism>
        <technical_mechanism>1. Expand Database</technical_mechanism>
        <technical_mechanism>2. Expand Server Objects</technical_mechanism>
        <technical_mechanism>3. Expand Linked Servers</technical_mechanism>
        <technical_mechanism>4. Expand Providers</technical_mechanism>
        <technical_mechanism>5. For each Provider listed:</technical_mechanism>
        <technical_mechanism>a. Right click on Provider name</technical_mechanism>
        <technical_mechanism>b. Select Properties</technical_mechanism>
        <technical_mechanism>c. Click on do not click the Enable check box for Name = Disallow adhoc access</technical_mechanism>
        <technical_mechanism>d. Click OK button</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015187 Rule Title: Linked server providers should not allow ad hoc access. STIG ID: DM6155 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19455-5' platform='ms-sql2005' modified='2013-02-11'>
      <description>Ad Hoc distributed queries should be configured appropriately</description>
      <parameters>
        <parameter>(1) ad hoc distributed queries</parameter>
        <parameter>(2) enable/disable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_CONFIGURE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015166 Rule Title: Database Engine Ad Hoc distributed queries should be disabled. STIG ID: DM6160 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19443-1' platform='ms-sql2005' modified='2013-02-11'>
      <description>Access to Analysis Services data sources should be configured appropriately.</description>
      <parameters>
        <parameter>(1) list of roles</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Analysis Services Database</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015180 Rule Title: Analysis Services permissions to data sources STIG ID: DM6193 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19882-0' platform='ms-sql2005' modified='2013-02-11'>
      <description>Database TRUSTWORTHY status for a specific database should be configured appropriately</description>
      <parameters>
        <parameter>(1) database name</parameter>
        <parameter>(2) SET TRUSTWORTHY [on | off]</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) ALTER DATABASE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015173 Rule Title: Database TRUSTWORTHY status should be authorized and documented or set to off. STIG ID: DM6195 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19552-9' platform='ms-sql2005' modified='2013-02-11'>
      <description>The Agent XPs options should be configured appropriately</description>
      <parameters>
        <parameter>(1) Agent XPs</parameter>
        <parameter>(2) enable/disable</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_CONFIGURE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015210 Rule Title: The Agent XPs option should be set to disabled if not required. STIG ID: DM6198 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19944-8' platform='ms-sql2005' modified='2013-02-11'>
      <description>The SMO and DMO XPs options should be configured appropriately</description>
      <parameters>
        <parameter>(1) SMO and DMO XPs</parameter>
        <parameter>(2) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) EXEC SP_CONFIGURE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='DISA STIG SQL 2005 INS Version 8, Release 1.7 Benchmark Date: 27 August 2010'>Rule ID: V0015211 Title: The SMO and DMO SPs option should be set to disabled if not required. STIG ID: DM6199 Severity: CAT II Class: Unclass</reference>
      </references>
    </cce>
    <cce cce_id='CCE-116-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable VBA for Office applications" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) 2007: GPO Settings:Computer Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office 2007 System / Security Settings </technical_mechanism>
        <technical_mechanism>(2) Registry keys: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Office\12.0\Common\VbaOff 2003: </technical_mechanism>
        <technical_mechanism>(3) Computer Configuration\Administrative Templates\Microsoft Office 2003\Security Settings\Disable VBA for Office applications </technical_mechanism>
        <technical_mechanism>(4)  HKLM\Software\Policies\Microsoft\Office\11.0\Common - VbaOff </technical_mechanism>
        <technical_mechanism>(5)  User Configuration\Administrative Templates\Microsoft Office 2003\Security Settings\Disable VBA for Office applications </technical_mechanism>
        <technical_mechanism>(6)  HKCU\Software\Policies\Microsoft\Office\11.0\Common - VbaOff</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-116</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.124. Disable VBA for Office applications, Table 2.5. Disable VBA for Office applications</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Disable VBA for Office applications, Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\Disable VBA for Office applications</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:771</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>DisableVBAForOfficeApplications</reference>
      </references>
    </cce>
    <cce cce_id='CCE-908-4' platform='office2k7' modified='2013-02-11'>
      <description>The "ActiveX Control Initialization:" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1)  1 = Do not prompt | 4 = Prompt user to use control defaults | 6 = Prompt user to use persisted data</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) 2007: GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office 2007 system / Security /ActiveX Control InitializationSettings </technical_mechanism>
        <technical_mechanism>(2) Registry keys: HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\Common\Security\UFIControls 2003: </technical_mechanism>
        <technical_mechanism>(3) User Configuration\Administrative Templates\Microsoft Office 2003\Security Settings\ActiveX Control Initialization </technical_mechanism>
        <technical_mechanism>(4)  HKCU\Software\Policies\Microsoft\Office\Common\Security - UFIControls</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-908</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.3. ActiveX Control Initialization</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\ActiveX Control Initialization (1 | 2 | 3 | 4 | 5 | 6)</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:814</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>ActiveXControlInitialization</reference>
      </references>
    </cce>
    <cce cce_id='CCE-184-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Enable Customer Experience Improvement Program" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office 2007 / Privacy / Trust Center , Registry Keys: HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\12.0\Common\QMEnable</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-184</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.148. Enable Customer Experience Improvement Program</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Privacy\Trust Center\Enable Customer Experience Improvement Program</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:829</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>EnableCustomerExperienceImprovementProgram</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO184 - Office 2007 Rule ID: SV-18747r3_rule Vuln ID: V-17612: Disable the "Enable Customer Experience Improvement Program" for Office.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-276-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Enable Customer Experience Improvement Program" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office 2007 / Privacy / Trust Center </technical_mechanism>
        <technical_mechanism>(2) Registry keys: HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\12.0\Common\UpdateReliabilityData</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-276</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.23. Automatically receive small updates to improve reliability</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Privacy\Trust Center\Automatically receive small updates to improve reliability</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:1473</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>AutomaticallyReceiveSmallUpdatesToImproveReliability</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO185 - Office Rule ID: SV-18922r1_rule Vuln ID: V-17740: Disable Automatic receiving of small updates to improve reliability - Office.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-967-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Online content options" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1)  0 = Never show online content or entry points | 1 = Search only offline content whenever available | 2 = Search online content whenever available</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office 2007 system / Tools / Options / General / Service Options / Online Content </technical_mechanism>
        <technical_mechanism>(2) Registry keys: HKEY_CURRENT_USER\Softtware\Polices\Microsoft\Office\12.0\Common\Internet\UseOnlineContent</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-967</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.179. Online content options</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | Options | General | Service Options...\Online Content\Online content options (Never show online content or entry points | Search only offline content whenever available | Search online content whenever available)</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:1302</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>OnlineContentOptions</reference>
      </references>
    </cce>
    <cce cce_id='CCE-427-5' platform='office2k7' modified='2013-02-11'>
      <description>The "VBA Macro Warning Settings" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1)  1 = No Security checks for macros | 2 = Trust Bar warning for all macros | 3 = Trust Bar warning for digitally signed macros only | 4 = No Warnings for all macros but disable all macros</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office Access 2007 / Application Settings / Security / Trust Center </technical_mechanism>
        <technical_mechanism>(2) Registry keys: HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\12.0\Access\Security\VBAWarnings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-427</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.234. VBA Macro Warning Settings</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Application Settings\Security\Trust Center\VBA Macro Warning Settings (Trust Bar warning for all macros | Trust Bar warning for digitally signed macros only (unsigned macros will be disabled) | No Warnings for all macros but disable all macros | No Security checks for macros (Not recommended, code in all documents can run))</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:1403</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>VBAMacroWarningSettings-Access</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO304 - Access Rule ID: SV-18637r2_rule Vuln ID: V-17545: Enable Warning Bar settings for VBA macros contained in Access Files.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-649-4' platform='office2k7' modified='2013-02-11'>
      <description>The "VBA Macro Warning Settings" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1)  1 = No Security checks for macros | 2 = Trust Bar warning for all macros | 3 = Trust Bar warning for digitally signed macros only | 4 = No Warnings for all macros but disable all macros</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) 2007: GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office Excel 2007 / Excel Options / Security / Trust Center </technical_mechanism>
        <technical_mechanism>(2) Registry keys: HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\12.0\Excel\Security\VBAWarnings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-649</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.234. VBA Macro Warning Settings</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Security\Trust Center\VBA Macro Warning Settings (Trust Bar warning for all macros | Trust Bar warning for digitally signed macros only (unsigned macros will be disabled) | No Warnings for all macros but disable all macros | No Security checks for macros (Not recommended, code in all documents can run))</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:649</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>VBAMacroWarningSettings-Excel</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO304 - Excel Rule ID: SV-18638r2_rule Vuln ID: V-17545: Enable Warning Bar settings for VBA macros contained in Excel Files.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-862-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Trust access to Visual Basic Project" setting should be configured correctly for Excel 2007 and 2003.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) 2007GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office Excel 2007 / Excel Options / Security / Trust Center </technical_mechanism>
        <technical_mechanism>(2) Registry keys: HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\12.0\Excel\Security\AccessVBOM 2003:</technical_mechanism>
        <technical_mechanism>(3) Computer Configuration\Administrative Templates\Microsoft Office 2003\Security Settings\Excel: Trust access to Visual Basic Project </technical_mechanism>
        <technical_mechanism>(4)  HKLM\Software\Policies\Microsoft\Office\11.0\Excel\Security - AccessVBOM </technical_mechanism>
        <technical_mechanism>(5)  User Configuration\Administrative Templates\Microsoft Office Excel 2003\Tools\Macros\Security\Trust access to Visual Basic Project </technical_mechanism>
        <technical_mechanism>(6)  HKCU\Software\Policies\Microsoft\Office\11.0\Excel\Security - AccessVBOM</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-862</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.225. Trust access to Visual Basic Project</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Security\Trust Center\Trust access to Visual Basic Project</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:1560</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>TrustAccessToVisualBasicProject-Excel</reference>
      </references>
    </cce>
    <cce cce_id='CCE-567-8' platform='office2k7' modified='2013-02-11'>
      <description>The "VBA Macro Warning Settings" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1)  1 = No Security checks for macros | 2 = Trust Bar warning for all macros | 3 = Trust Bar warning for digitally signed macros only | 4 = No Warnings for all macros but disable all macros</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office PowerPoint 2007 / PowerPoint Options / Security / Trust Center </technical_mechanism>
        <technical_mechanism>(2) Registry keys: HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\VBAWarnings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-567</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.234. VBA Macro Warning Settings</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Security\Trust Center\VBA Macro Warning Settings (Trust Bar warning for all macros | Trust Bar warning for digitally signed macros only (unsigned macros will be disabled) | No Warnings for all macros but disable all macros | No Security checks for macros (Not recommended, code in all documents can run))</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:654</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>VBAMacroWarningSettings-PowerPoint</reference>
      </references>
    </cce>
    <cce cce_id='CCE-68-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Trust access to Visual Basic Project" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office PowerPoint 2007 / PowerPoint Options / Security / Trust Center </technical_mechanism>
        <technical_mechanism>(2) Registry keys: HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\AccessVBOM</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-68</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.225. Trust access to Visual Basic Project</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Security\Trust Center\Trust access to Visual Basic Project</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:665</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>TrustAccessToVisualBasicProject-PowerPoint</reference>
      </references>
    </cce>
    <cce cce_id='CCE-537-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable Remember Passwords" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Classic Administrative Templates\Microsoft Office Outlook 2007\Security\Disable Remember Passwords</technical_mechanism>
        <technical_mechanism>(2) HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security\EnableRememberPwd</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-537</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Classic Administrative Templates\Microsoft Office Outlook 2007\Security\Disable Remember Passwords</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:1298</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>DisableRememberPassword</reference>
      </references>
    </cce>
    <cce cce_id='CCE-786-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Configure Add-In Trust Level" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1)  0 = Trust all or use Exchange settings if present  |  1 = Trust all loaded and installed COM addins  |  2 = Do NOT trust loaded and installed COM addins</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Classic Administrative Templates\Microsoft Office Outlook 2007\Security\Configure Add-In Trust Level</technical_mechanism>
        <technical_mechanism>(2) HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\12.0\Outlook\Security\AddinTrust</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-786</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.72. Configure trusted add-ins</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Programmatic Security\Trusted Add-insConfigure trusted add-ins</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:1390</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>ConfigureAddInTrustLevel</reference>
      </references>
    </cce>
    <cce cce_id='CCE-937-3' platform='office2k7' modified='2013-02-11' deprecated='true'>
      <description>DEPRECATED in favor of CCE-537-1.</description>
      <parameters />
      <technical_mechanisms />
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-937</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Minimum encryption settings" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office Outlook 2007 / Security / Cryptography </technical_mechanism>
        <technical_mechanism>(2) Registry keys: HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\12.0\Outlook\Security\MinEncKey</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-13</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.173. Minimum encryption settings</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Minimum encryption settings</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:661</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>MinimumEncryptionSettings</reference>
      </references>
    </cce>
    <cce cce_id='CCE-316-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Do not check e-mail address against address of certificates being using" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office Outlook 2007 / Security / Cryptography </technical_mechanism>
        <technical_mechanism>(2) Registry keys: HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\12.0\Outlook\Security\SupressNameChecks</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-316</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.134. Do not check e-mail address against address of certificates being using</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Do not check e-mail address against address of certificates being used</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:1399</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>DoNotCheckEmailAddressAgainstAddressOfCertificatesBeingUsed</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Send all signed messages as clear signed messages" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) 2007: GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office Outlook 2007 / Security / Cryptography </technical_mechanism>
        <technical_mechanism>(2) Registry keys: HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\12.0\Outlook\Security\ClearSign 2003: </technical_mechanism>
        <technical_mechanism>(3) User Configuration\Administrative Templates\Microsoft Office Outlook 2003\Tools\Options\Security\Cryptography\Send all signed messages as clear signed messages </technical_mechanism>
        <technical_mechanism>(4)  HKCU\Software\Policies\Microsoft\Office\11.0\Outlook\Security - ClearSign</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-14</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.214. Send all signed messages as clear signed messages</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Send all signed messages as clear signed messages</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:1388</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>SendAllSignedMessagesAsClearSignedMessages</reference>
      </references>
    </cce>
    <cce cce_id='CCE-153-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Request an S/MIME receipt for all S/MIME signed messages" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office Outlook 2007 / Security / Cryptography </technical_mechanism>
        <technical_mechanism>(2) Registry keys: HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\12.0\Outlook\Security\RequestSecureReceipt</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-153</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.198. Request an S/MIME receipt for all S/MIME signed messages</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Request an S/MIME receipt for all S/MIME signed messages</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:705</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>RequestAnSMIMEReceiptForAllSMIMESignedMessages</reference>
      </references>
    </cce>
    <cce cce_id='CCE-345-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Do not display 'Publish to GAL' button" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) 2007: GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office Outlook 2007 / Security / Cryptography </technical_mechanism>
        <technical_mechanism>(2) Registry keys: HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\12.0\Outlook\Security\PublishToGalDisabled 2003: </technical_mechanism>
        <technical_mechanism>(3) User Configuration\Administrative Templates\Microsoft Office Outlook 2003\Tools\Options\Security\Cryptography\Disable 'Publish to GAL' button </technical_mechanism>
        <technical_mechanism>(4)  HKCU\Software\Policies\Microsoft\office\11.0\outlook\Security - PublishToGalDisabled</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-345</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.135. Do not display 'Publish to GAL' button</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Do not display 'Publish to GAL' button</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:741</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>DoNotDisplayPublishToGALButton</reference>
      </references>
    </cce>
    <cce cce_id='CCE-700-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Signature Warning" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1)  0 = Let user decide if they want to be warned | 1 = Always warn about invalid signatures | 2 = Never warn about invalid signatures</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) 2007: GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office Outlook 2007 / Security / Cryptography </technical_mechanism>
        <technical_mechanism>(2) Registry keys: HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\12.0\Outlook\Security\WarnAboutInvalid 2003: </technical_mechanism>
        <technical_mechanism>(3) User Configuration\Administrative Templates\Microsoft Office Outlook 2003\Tools\Options\Security\Cryptography\Signature Warning </technical_mechanism>
        <technical_mechanism>(4)  HKCU\Software\Policies\Microsoft\Office\11.0\Outlook\Security - WarnAboutInvalid</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-700</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.220. Signature Warning</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Signature Warning (Let user decide if they want to be warned | Always warn about invalid signatures | Never warn about invalid signatures)</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:756</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>SignatureWarning</reference>
      </references>
    </cce>
    <cce cce_id='CCE-695-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Enable Cryptography Icons" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) 2007: GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office Outlook 2007 / Security / Cryptography </technical_mechanism>
        <technical_mechanism>(2) Registry keys: HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\12.0\Outlook\Security\ConvertSMIMEBlobSignedIcons 2003: (3) User Configuration\Administrative Templates\Microsoft Office Outlook 2003\Tools\Options\Security\Cryptography\Enable cryptography icons </technical_mechanism>
        <technical_mechanism>(4)  HKCU\Software\Policies\Microsoft\Office\11.0\Outlook\Security - ConvertSMIMEBlobSignedIcons</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-695</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Enable Cryptography Icons</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:1716</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>EnableCryptographyIcons</reference>
      </references>
    </cce>
    <cce cce_id='CCE-395-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Retrieving CRLs (Certificate Revocation Lists)" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1)  0 = Use system Default | 1 = When online always retreive the CRL | 2 = Never retreive the CRL</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office Outlook 2007 / Security / Cryptography / Signature Status Dialog Box </technical_mechanism>
        <technical_mechanism>(2) Registry keys: HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\12.0\Outlook\Security\UseCRLChasing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-395</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.204. Retrieving CRLs (Certificate Revocation Lists)</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Signature Status dialog box\Retrieving CRLs (Certificate Revocation Lists) (Use system Default | When online always retreive the CRL | Never retreive the CRL)</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:1700</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>RetrievingCRLs</reference>
      </references>
    </cce>
    <cce cce_id='CCE-659-3' platform='office2k7' modified='2013-02-11'>
      <description>The "VBA Macro Warning Settings" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1)  1 = No Security checks for macros | 2 = Trust Bar warning for all macros | 3 = Trust Bar warning for digitally signed macros only | 4 = No Warnings for all macros but disable all macros</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office Word 2007 / Word Options / Security / Trust Center </technical_mechanism>
        <technical_mechanism>(2) Registry keys: HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\12.0\Word\Security\VBAWarnings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-659</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.234. VBA Macro Warning Settings</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Security\Trust Center\VBA Macro Warning Settings (Trust Bar warning for all macros | Trust Bar warning for digitally signed macros only (unsigned macros will be disabled) | No Warnings for all macros but disable all macros | No )</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:1350</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>VBMacroWarningSettings-Word</reference>
      </references>
    </cce>
    <cce cce_id='CCE-703-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Trust access to Visual Basic Project" setting should be configured correctly for Word 2007 and 2003.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) 2007: GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office Word 2007 / Word Options / Security / Trust Center </technical_mechanism>
        <technical_mechanism>(2) Registry keys: HKEY_CURRENT_USER\Software\Policies\Policies\Microsoft\Office\12.0\Word\Security\AccessVBOM 2003: </technical_mechanism>
        <technical_mechanism>(3) Computer Configuration\Administrative Templates\Microsoft Office 2003\Security Settings\Word: Trust access to Visual Basic Project </technical_mechanism>
        <technical_mechanism>(4)  HKLM\Software\Policies\Microsoft\Office\11.0\Word\Security - AccessVBOM </technical_mechanism>
        <technical_mechanism>(5)  User Configuration\Administrative Templates\Microsoft Office Word 2003\Tools\Macro\Security\Trust access to Visual Basic Project </technical_mechanism>
        <technical_mechanism>(6)  HKCU\Software\Policies\Microsoft\Office\11.0\Word\Security - AccessVBOM</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-703</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.225. Trust access to Visual Basic Project</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Security\Trust Center\Trust access to Visual Basic Project</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:1713</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>TrustAccessToVisualBasicProject-Word</reference>
      </references>
    </cce>
    <cce cce_id='CCE-173-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Warn before printing, saving or sending a file that contains tracked changes or comments" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) 2007: GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office Word 2007 / Word Options / Security </technical_mechanism>
        <technical_mechanism>(2) Registry keys: HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\12.0\Word\Options\vpref\fWarnRevisions_1805_1 2003: </technical_mechanism>
        <technical_mechanism>(2) User Configuration\Administrative Templates\Microsoft Office Word 2003\Tools\Options\Security\Warn before printing or saving or sending a file that contains tracked changes or comments </technical_mechanism>
        <technical_mechanism>(3)  HKCU\Software\Policies\Microsoft\Office\11.0\Word\Options\vpre</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-173</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:788</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>WarnBeforePrintingSavingOrSendingAFileThatContainsTrackedChangesOrComments</reference>
      </references>
    </cce>
    <cce cce_id='CCE-784-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Block updates from the Office Update Site from applying" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) GPO Settings:User Configuration / Administrative Templates / Classic Administrative Templates / Microsoft Office 2007 / Miscellaneous </technical_mechanism>
        <technical_mechanism>(2) Registry keys: HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\Common\OfficeUpdate\BlockUpdates</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-784</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.64. Block updates from the Office Update Site from applying</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Miscellaneous\Block updates from the Office Update Site from applying</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 OVAL (SCAP-Office2007-OVAL-Beta-v1.xml)'>oval:org.mitre.oval:def:1755</reference>
        <reference resource_id='NIST SCAP Microsoft Office 2007 XCCDF (SCAP-Office2007-XCCDF-Beta-v1.xml )'>BlockUpdatesFromTheOfficeUpdateSiteFromApplying</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO213 - Office 2007 Rule ID: SV-18669r3_rule Vuln ID: V-17565: Block Office from receiving updates from the Office Update Site.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1395-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Underline hyperlinks" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Application Settings\Web Options\General\Underline hyperlinks </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\Internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1395</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.230. Underline hyperlinks</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Application Settings\Web Options\General\Underline hyperlinks</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1137-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Number of documents in the Recent Documents list (0-9)" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Application Settings\General\General\Number of documents in the Recent Documents list (0-9) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1137</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Application Settings\General\General\Number of documents in the Recent Documents list (0-9)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1423-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable Trust Bar Notification for unsigned application add-ins" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Application Settings\Security\Trust Center\Disable Trust Bar Notification for unsigned application add-ins </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1423</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.120. Disable Trust Bar Notification for unsigned application add-ins</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Application Settings\Security\Trust Center\Disable Trust Bar Notification for unsigned application add-ins</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO131 - Access Rule ID: SV-18219r2_rule Vuln ID: V-17187: Disable Trust Bar Notification for unsigned application add-ins - Access</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1238-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable all application add-ins" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Application Settings\Security\Trust Center\Disable all application add-ins </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1238</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.87. Disable all application add-ins</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Application Settings\Security\Trust Center\Disable all application add-ins</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1476-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Require that application add-ins are signed by Trusted Publisher" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Application Settings\Security\Trust Center\Require that application add-ins are signed by Trusted Publisher </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1476</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.200. Require that application add-ins are signed by Trusted Publisher</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Application Settings\Security\Trust Center\Require that application add-ins are signed by Trusted Publisher</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1520-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable all trusted locations" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Application Settings\Security\Trust Center\Trusted LocationsDisable all trusted locations </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\Security\Trusted Locations</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1520</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.89. Disable all trusted locations</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Application Settings\Security\Trust Center\Trusted Locations\Disable all trusted locations</reference>
      </references>
    </cce>
    <cce cce_id='CCE-780-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Allow Trusted Locations not on the computer" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Application Settings\Security\Trust Center\Trusted Locations\Allow Trusted Locations not on the computer </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\Security\Trusted Locations</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-780</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.11. Allow Trusted Locations not on the computer</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Application Settings\Security\Trust Center\Trusted Locations\Allow Trusted Locations not on the computer</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1214-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Modal Trust Decision Only" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Application Settings\Security\Trust Center\Trusted Locations\Modal Trust Decision Only </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\Security\Trusted Locations</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1214</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.176. Modal Trust Decision Only</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Application Settings\Security\Trust Center\Trusted Locations\Modal Trust Decision Only</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1370-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1370</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1268-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Office Button | E-Mail" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Office Button | E-Mail </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1268</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Office Button | E-Mail</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1400-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Office Button | Access Options | Customize | All Commands | Insert Hyperlink" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Office Button | Access Options | Customize | All Commands | Insert Hyperlink </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1400</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Office Button | Access Options | Customize | All Commands | Insert Hyperlink</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1440-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Database Tools | Database Tools | Encrypt with Password" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Database Tools | Database Tools | Encrypt with Password </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1440</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Database Tools | Database Tools | Encrypt with Password</reference>
      </references>
    </cce>
    <cce cce_id='CCE-581-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Database Tools | Administer | Users and Permission | User and Group Permissions" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Database Tools | Administer | Users and Permission | User and Group Permissions </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-581</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Database Tools | Administer | Users and Permission | User and Group Permissions</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1480-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Database Tools | Administer | Users and Permissions | User and Group Accounts" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Database Tools | Administer | Users and Permissions | User and Group Accounts </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1480</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Database Tools | Administer | Users and Permissions | User and Group Accounts</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1489-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Database Tools | Administer | Users and Permission | User-Level Security Wizard..." setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Database Tools | Administer | Users and Permission | User-Level Security Wizard... </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1489</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Database Tools | Administer | Users and Permission | User-Level Security Wizard...</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1392-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Database Tools | Database Tools | Encode/Decode Database" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Database Tools | Database Tools | Encode/Decode Database </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1392</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Database Tools | Database Tools | Encode/Decode Database</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1414-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Database Tools | Macro | Visual Basic" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Database Tools | Macro | Visual Basic </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1414</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Database Tools | Macro | Visual Basic</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1418-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Database Tools | Macro | Run Macro" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Database Tools | Macro | Run Macro </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1418</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Database Tools | Macro | Run Macro</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1405-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Database Tools | Macro | Convert Macros to Visual Basic" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Database Tools | Macro | Convert Macros to Visual Basic </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1405</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Database Tools | Macro | Convert Macros to Visual Basic</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1550-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Database Tools | Macro | Create Shortcut Menu from Macro" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Database Tools | Macro | Create Shortcut Menu from Macro </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1550</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Database Tools | Macro | Create Shortcut Menu from Macro</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1075-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable shortcut keys" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable shortcut keys </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\DisabledShortcutKeysCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1075</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.114. Disable shortcut keys</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable shortcut keys</reference>
      </references>
    </cce>
    <cce cce_id='CCE-709-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Ctrl+K (Office Button | Access Options | Customize | All Commands | Insert Hyperlinks)" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Ctrl+K (Office Button | Access Options | Customize | All Commands | Insert Hyperlinks) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\DisabledShortcutKeysCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-709</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.114. Disable shortcut keys</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Ctrl+K (Office Button | Access Options | Customize | All Commands | Insert Hyperlinks)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1502-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Alt+F11 (Database Tools | Macro | Visual Basic)" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Alt+F11 (Database Tools | Macro | Visual Basic) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\DisabledShortcutKeysCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1502</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.114. Disable shortcut keys</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Disable items in user interface\Predefined\Disable commands - Alt+F11 (Database Tools | Macro | Visual Basic)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1260-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Default file format (Access 2007 | Access 2002-2003)" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Miscellaneous\Default file format (Access 2007 | Access 2002-2003) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1260</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.80. Default file format</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Miscellaneous\Default file format (Access 2007 | Access 2002-2003)</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO136 - Access Rule ID: SV-18706r2_rule Vuln ID: V-17584: Set the default saved file format for Access.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1510-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Do not prompt to convert older databases" setting should be configured correctly for Access 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Access 2007\Miscellaneous\Do not prompt to convert older databases </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Access\Settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1510</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.141. Do not prompt to convert older databases</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Access 2007\Miscellaneous\Do not prompt to convert older databases</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1532-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Internet and network paths as hyperlinks" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Proofing\Autocorrect Options\Internet and network paths as hyperlinks </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1532</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.164. Internet and network paths as hyperlinks</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Proofing\Autocorrect Options\Internet and network paths as hyperlinks</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1039-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Save Excel files as (Excel Workbook (*.xlsx) | Excel Macro-Enabled Workbook (*.xlsm) | Excel Binary Workbook (*.xlsb) | Web Page (*.htm; *.html) | Excel 97-2003 Workbook (*.xls) | Excel 5.0/95 Workbook (*.xls))" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Save\Save Excel files as (Excel Workbook (*.xlsx) | Excel Macro-Enabled Workbook (*.xlsm) | Excel Binary Workbook (*.xlsb) | Web Page (*.htm; *.html) | Excel 97-2003 Workbook (*.xls) | Excel 5.0/95 Workbook (*.xls)) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1039</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.211. Save Excel files as</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Save\Save Excel files as (Excel Workbook (*.xlsx) | Excel Macro-Enabled Workbook (*.xlsm) | Excel Binary Workbook (*.xlsb) | Web Page (*.htm; *.html) | Excel 97-2003 Workbook (*.xls) | Excel 5.0/95 Workbook (*.xls))</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1295-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable AutoRepublish" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Save\Disable AutoRepublish </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1295</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.91. Disable AutoRepublish</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Save\Disable AutoRepublish</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1334-2' platform='office2k7' modified='2013-02-11'>
      <description>The "AutoRepublish Warning Alert (Always show the alert before publishing | Never show the alert before publishing)" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Save\AutoRepublish Warning Alert (Always show the alert before publishing | Never show the alert before publishing) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1334</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.25. AutoRepublish Warning Alert</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Save\AutoRepublish Warning Alert (Always show the alert before publishing | Never show the alert before publishing)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1308-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Determine whether to force encrypted macros to be scanned in Microsoft Excel Open XML workbooks" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Security\Determine whether to force encrypted macros to be scanned in Microsoft Excel Open XML workbooks </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1308</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.81. Determine whether to force encrypted macros to be scanned in Microsoft Excel Open XML workbooks</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Security\Determine whether to force encrypted macros to be scanned in Microsoft Excel Open XML workbooks</reference>
      </references>
    </cce>
    <cce cce_id='CCE-616-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Force file extension to match file type (Allow different | Allow different, but warn | Always match file type)" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Security\Force file extension to match file type (Allow different | Allow different, but warn | Always match file type) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-616</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.155. Force file extension to match file type</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Security\Force file extension to match file type (Allow different | Allow different, but warn | Always match file type)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1246-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Store macro in Personal Macro Workbook by default" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Security\Trust Center\Store macro in Personal Macro Workbook by default </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1246</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.221. Store macro in Personal Macro Workbook by default</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Security\Trust Center\Store macro in Personal Macro Workbook by default</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1251-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable all application add-ins" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Security\Trust Center\Disable all application add-ins </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1251</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.87. Disable all application add-ins</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Security\Trust Center\Disable all application add-ins</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1524-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Require that application add-ins are signed by Trusted Publisher" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Security\Trust Center\Require that application add-ins are signed by Trusted Publisher </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1524</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.200. Require that application add-ins are signed by Trusted Publisher</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Security\Trust Center\Require that application add-ins are signed by Trusted Publisher</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1422-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable Trust Bar Notification for unsigned application add-ins" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Security\Trust Center\Disable Trust Bar Notification for unsigned application add-ins </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1422</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.120. Disable Trust Bar Notification for unsigned application add-ins</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Security\Trust Center\Disable Trust Bar Notification for unsigned application add-ins</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1444-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Allow Trusted Locations not on the computer" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Security\Trust Center\Trusted LocationsAllow Trusted Locations not on the computer </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security\Trusted Locations</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1444</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.11. Allow Trusted Locations not on the computer</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Security\Trust Center\Trusted LocationsAllow Trusted Locations not on the computer</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1449-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable all trusted locations" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Security\Trust Center\Trusted LocationsDisable all trusted locations </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security\Trusted Locations</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1449</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.89. Disable all trusted locations</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Security\Trust Center\Trusted LocationsDisable all trusted locations</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1471-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Ignore other applications " setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Advanced\Ignore other applications  </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Options\BinaryOptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1471</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.159. Ignore other applications</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Advanced\Ignore other applications</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1119-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Ask to update automatic links" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Advanced\Ask to update automatic links </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1119</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.17. Ask to update automatic links</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Advanced\Ask to update automatic links</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1378-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Number of documents in the Recent Documents list (0-17)" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Advanced\Number of documents in the Recent Documents list (0-17) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\File MRU</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1378</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Advanced\Number of documents in the Recent Documents list (0-17)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1277-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Save any additional data necessary to maintain formulas" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Advanced\Web Options…\GeneralSave any additional data necessary to maintain formulas </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1277</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.210. Save any additional data necessary to maintain formulas</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Advanced\Web Options…\GeneralSave any additional data necessary to maintain formulas</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1464-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Load pictures from Web pages not created in Excel" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Advanced\Web Options…\GeneralLoad pictures from Web pages not created in Excel </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1464</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.169. Load pictures from Web pages not created in Excel</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Excel Options\Advanced\Web Options…\GeneralLoad pictures from Web pages not created in Excel</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1094-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Do not show data extraction options when opening corrupt workbooks" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Data Recovery\Do not show data extraction options when opening corrupt workbooks </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1094</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.143. Do not show data extraction options when opening corrupt workbooks</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Data Recovery\Do not show data extraction options when opening corrupt workbooks</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1129-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Assume structured storage format of workbook is intact when recovering data" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Data Recovery\Assume structured storage format of workbook is intact when recovering data </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1129</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Data Recovery\Assume structured storage format of workbook is intact when recovering data</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1389-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Corrupt formula conversion (Convert unrecoverable references to: values | #REF or #NAME)" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Data Recovery\Corrupt formula conversion (Convert unrecoverable references to: values | #REF or #NAME) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1389</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Data Recovery\Corrupt formula conversion (Convert unrecoverable references to: values | #REF or #NAME)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1433-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Connection File Locations" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Data Access Security\Connection File Locations </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\Common\Server Links\Published</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1433</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Data Access Security\Connection File Locations</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1323-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Automatic Query Refresh (Prompt for all workbooks | Do not prompt; do not allow auto refresh | Do not prompt; allow auto refresh)" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Data Access Security\Automatic Query Refresh (Prompt for all workbooks | Do not prompt; do not allow auto refresh | Do not prompt; allow auto refresh) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\Common\Server Links\Published</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1323</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Data Access Security\Automatic Query Refresh (Prompt for all workbooks | Do not prompt; do not allow auto refresh | Do not prompt; allow auto refresh)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1469-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1469</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1473-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Office Button | Excel Options | Customize | All Commands | Save as Web Page" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Office Button | Excel Options | Customize | All Commands | Save as Web Page </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1473</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Office Button | Excel Options | Customize | All Commands | Save as Web Page</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1499-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Office Button | Excel Options | Customize | All Commands | Web Page Preview" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Office Button | Excel Options | Customize | All Commands | Web Page Preview </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1499</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Office Button | Excel Options | Customize | All Commands | Web Page Preview</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1024-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Office Button | Send | Email" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Office Button | Send | Email </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1024</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Office Button | Send | Email</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1530-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Insert | Links | Hyperlink" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Insert | Links | Hyperlink </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1530</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Insert | Links | Hyperlink</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1120-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Review | Changes | Protect Sheet" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Review | Changes | Protect Sheet </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1120</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Review | Changes | Protect Sheet</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1252-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Review | Changes | Protect Workbook" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Review | Changes | Protect Workbook </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1252</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Review | Changes | Protect Workbook</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1151-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Review | Changes | Protect and Share Workbook" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Review | Changes | Protect and Share Workbook </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1151</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Review | Changes | Protect and Share Workbook</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1301-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - View | Macros | Macros" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - View | Macros | Macros </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1301</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - View | Macros | Macros</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1310-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Developer | Code | Macros" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Macros </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1310</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Macros</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1213-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Developer | Code | Record Macro" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Record Macro </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1213</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Record Macro</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1362-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Developer | Code | Macro Security" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Macro Security </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1362</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Macro Security</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1156-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Developer | Code | Visual Basic" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Visual Basic </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1156</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Visual Basic</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1429-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Office Button | Excel Options | Customize | All Commands | Document Location" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Office Button | Excel Options | Customize | All Commands | Document Location </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1429</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable commands - Office Button | Excel Options | Customize | All Commands | Document Location</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1182-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable shortcut keys" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable shortcut keys </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\DisabledShortcutKeysCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1182</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.114. Disable shortcut keys</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable shortcut keys</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1525-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable shortcut keys - Ctrl+K (Insert | Links |  Hyperlink)" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable shortcut keys - Ctrl+K (Insert | Links |  Hyperlink) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\DisabledShortcutKeysCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1525</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.114. Disable shortcut keys</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable shortcut keys - Ctrl+K (Insert | Links |  Hyperlink)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1547-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable shortcut keys - Alt+F8 (Developer | Code | Macros)" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable shortcut keys - Alt+F8 (Developer | Code | Macros) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\DisabledShortcutKeysCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1547</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.114. Disable shortcut keys</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable shortcut keys - Alt+F8 (Developer | Code | Macros)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1300-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable shortcut keys - Alt+F11 (Developer | Code | Visual Basic)" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable shortcut keys - Alt+F11 (Developer | Code | Visual Basic) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\DisabledShortcutKeysCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1300</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.114. Disable shortcut keys</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Disable items in user interface\Predefined\Disable shortcut keys - Alt+F11 (Developer | Code | Visual Basic)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1331-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of pre-release versions of file formats new to Excel 2007" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Open\Block opening of pre-release versions of file formats new to Excel 2007 </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1331</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.34. Block opening of files created by pre-release versions of Excel 2007</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Open\Block opening of pre-release versions of file formats new to Excel 2007</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1468-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of Open XML file types" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Open\Block opening of Open XML file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1468</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.38. Block opening of Open XML file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Open\Block opening of Open XML file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1490-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of Binary 12 file types" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Open\Block opening of Binary 12 file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1490</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.29. Block opening of Binary 12 file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Open\Block opening of Binary 12 file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1512-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of Binary file types" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Open\Block opening of Binary file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1512</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.30. Block opening of Binary file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Open\Block opening of Binary file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1543-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of Html and Xmlss files types" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Open\Block opening of Html and Xmlss files types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1543</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.35. Block opening of Html and Xmlss files types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Open\Block opening of Html and Xmlss files types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1195-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of Xml file types" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Open\Block opening of Xml file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1195</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.49. Block opening of Xml file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Open\Block opening of Xml file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-554-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of DIF and SYLK file types" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Open\Block opening of DIF and SYLK file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-554</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.32. Block opening of DIF and SYLK file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Open\Block opening of DIF and SYLK file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1415-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of Text file types" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Open\Block opening of Text file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1415</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.46. Block opening of Text file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Open\Block opening of Text file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1437-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of Xll file type" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Open\Block opening of Xll file type </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1437</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.48. Block opening of Xll file type</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Open\Block opening of Xll file type</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1446-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Block saving of Open Xml file types" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Save\Block saving of Open Xml file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security\FileSaveBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1446</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.57. Block saving of Open Xml file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Save\Block saving of Open Xml file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1098-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Block saving of Binary12 file types" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Save\Block saving of Binary12 file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security\FileSaveBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1098</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.52. Block saving of Binary12 file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Save\Block saving of Binary12 file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-562-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Block saving of Binary file types" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Save\Block saving of Binary file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security\FileSaveBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-562</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Save\Block saving of Binary file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1507-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Block saving of Html and Xmlss file types" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Save\Block saving of Html and Xmlss file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security\FileSaveBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1507</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.55. Block saving of Html and Xmlss file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Save\Block saving of Html and Xmlss file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1406-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Block saving Xml file types" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Save\Block saving Xml file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security\FileSaveBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1406</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Save\Block saving Xml file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-573-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Block saving DIF and SYLK file types" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Save\Block saving DIF and SYLK file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security\FileSaveBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-573</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.50. Block saving DIF and SYLK file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Save\Block saving DIF and SYLK file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1336-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Block saving of Text file types" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Save\Block saving of Text file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security\FileSaveBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1336</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.60. Block saving of Text file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Block file formats\Save\Block saving of Text file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1230-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Locally cache network file storages" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Miscellaneous\Locally cache network file storages </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1230</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Miscellaneous\Locally cache network file storages</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1375-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Locally cache PivotTable reports" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Miscellaneous\Locally cache PivotTable reports </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1375</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Miscellaneous\Locally cache PivotTable reports</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1380-5' platform='office2k7' modified='2013-02-11'>
      <description>The "OLAP PivotTable User Defined Function (UDF) security setting (Allow ALL UDFs | Allow safe UDFs only | Allow NO UDFs)" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Miscellaneous\OLAP PivotTable User Defined Function (UDF) security setting (Allow ALL UDFs | Allow safe UDFs only | Allow NO UDFs) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1380</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Miscellaneous\OLAP PivotTable User Defined Function (UDF) security setting (Allow ALL UDFs | Allow safe UDFs only | Allow NO UDFs)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1376-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Recognize SmartTags" setting should be configured correctly for Excel 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Excel 2007\Miscellaneous\Recognize SmartTags </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1376</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Excel 2007\Miscellaneous\Recognize SmartTags</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1398-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Number of documents in the Recent Documents list (0 - 9)" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Tools | Options\General\Number of documents in the Recent Documents list (0 - 9) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1398</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Tools | Options\General\Number of documents in the Recent Documents list (0 - 9)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-569-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Offline Mode status (Disabled | Enabled, InfoPath in Offline Mode | Enabled, InfoPath not in Offline Mode)" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Tools | Options\Advanced\Offline\Offline Mode status (Disabled | Enabled, InfoPath in Offline Mode | Enabled, InfoPath not in Offline Mode) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Editor\Offline</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-569</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.178. Offline Mode status</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Tools | Options\Advanced\Offline\Offline Mode status (Disabled | Enabled, InfoPath in Offline Mode | Enabled, InfoPath not in Offline Mode)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1065-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1065</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1361-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - File | Print" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - File | Print </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1361</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - File | Print</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1096-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - File | Send to Mail Recipient" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - File | Send to Mail Recipient </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1096</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - File | Send to Mail Recipient</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1391-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - File | Open from SharePoint Site" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - File | Open from SharePoint Site </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1391</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - File | Open from SharePoint Site</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1519-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - File | Print Preview" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - File | Print Preview </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1519</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - File | Print Preview</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1523-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - File | Page Setup" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - File | Page Setup </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1523</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - File | Page Setup</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1171-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Insert | Hyperlinks..." setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - Insert | Hyperlinks... </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1171</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - Insert | Hyperlinks...</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1457-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Tools | Set Language" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - Tools | Set Language </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1457</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - Tools | Set Language</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1426-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Tools | Customize..." setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - Tools | Customize... </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1426</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - Tools | Customize...</reference>
      </references>
    </cce>
    <cce cce_id='CCE-805-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Tools | Options..." setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - Tools | Options... </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-805</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - Tools | Options...</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1453-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Help | Microsoft Office Online" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - Help | Microsoft Office Online </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1453</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - Help | Microsoft Office Online</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1351-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Office Diagnostics" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - Office Diagnostics </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1351</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - Office Diagnostics</reference>
      </references>
    </cce>
    <cce cce_id='CCE-620-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Help | Activate Product..." setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - Help | Activate Product... </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-620</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - Help | Activate Product...</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1017-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Print Default" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - Print Default </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1017</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable commands - Print Default</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1021-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable shortcut keys" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable shortcut keys </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\DisabledShortcutKeysCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1021</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.114. Disable shortcut keys</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable shortcut keys</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1299-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable shortcut keys - Print Shortcut (Ctrl+P)" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable shortcut keys - Print Shortcut (Ctrl+P) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\DisabledShortcutKeysCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1299</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.114. Disable shortcut keys</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable shortcut keys - Print Shortcut (Ctrl+P)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1197-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable shortcut keys - Insert Hyperlink Shortcut (Ctrl+K)" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable shortcut keys - Insert Hyperlink Shortcut (Ctrl+K) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\DisabledShortcutKeysCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1197</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.114. Disable shortcut keys</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Predefined\Disable shortcut keys - Insert Hyperlink Shortcut (Ctrl+K)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-704-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Control behavior for Windows SharePoint Services gradual upgrade (Allow redirections to any location | Allow redirections to Intranet only | Block all redirections)" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Control behavior for Windows SharePoint Services gradual upgrade (Allow redirections to any location | Allow redirections to Intranet only | Block all redirections) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-704</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.73. Control behavior for Windows SharePoint Services gradual upgrade</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Control behavior for Windows SharePoint Services gradual upgrade (Allow redirections to any location | Allow redirections to Intranet only | Block all redirections)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1105-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable opening of solutions from the Internet security zone" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Disable opening of solutions from the Internet security zone </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1105</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.109. Disable opening of solutions from the Internet security zone</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Disable opening of solutions from the Internet security zone</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1114-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable fully trusted solutions full access to computer" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Disable fully trusted solutions full access to computer </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1114</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.102. Disable fully trusted solutions full access to computer</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Disable fully trusted solutions full access to computer</reference>
      </references>
    </cce>
    <cce cce_id='CCE-761-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Allow the use of ActiveX Custom Controls in InfoPath forms" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Allow the use of ActiveX Custom Controls in InfoPath forms </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-761</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Allow the use of ActiveX Custom Controls in InfoPath forms</reference>
      </references>
    </cce>
    <cce cce_id='CCE-739-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Run forms in restricted mode if they do not specify a publish location and use only features introduced before InfoPath 2003 SP1" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Run forms in restricted mode if they do not specify a publish location and use only features introduced before InfoPath 2003 SP1 </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-739</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Run forms in restricted mode if they do not specify a publish location and use only features introduced before InfoPath 2003 SP1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1259-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Allow file types as attachments to forms" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Allow file types as attachments to forms </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1259</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.7. Allow file types as attachments to forms</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Allow file types as attachments to forms</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1267-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Block specific file types as attachments to forms" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Block specific file types as attachments to forms </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1267</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.62. Block specific file types as attachments to forms</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Block specific file types as attachments to forms</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1060-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Prevent users from allowing unsafe file types to be attached to forms" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Prevent users from allowing unsafe file types to be attached to forms </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1060</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.186. Prevent users from allowing unsafe file types to be attached to forms</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Prevent users from allowing unsafe file types to be attached to forms</reference>
      </references>
    </cce>
    <cce cce_id='CCE-955-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Display a warning that a form is digitally signed" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Display a warning that a form is digitally signed </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-955</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Display a warning that a form is digitally signed</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1479-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Control behavior when opening forms in the Internet security zone (Block | Prompt | Allow)" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Control behavior when opening forms in the Internet security zone (Block | Prompt | Allow) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Open Behaviors</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1479</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.74. Control behavior when opening forms in the Internet security zone</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Control behavior when opening forms in the Internet security zone (Block | Prompt | Allow)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1360-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Control behavior when opening forms in the Intranet security zone (Block | Prompt | Allow)" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Control behavior when opening forms in the Intranet security zone (Block | Prompt | Allow) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Open Behaviors</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1360</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.75. Control behavior when opening forms in the Intranet security zone</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Control behavior when opening forms in the Intranet security zone (Block | Prompt | Allow)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1386-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Control behavior when opening forms in the Local Machine security zone (Block | Prompt | Allow)" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Control behavior when opening forms in the Local Machine security zone (Block | Prompt | Allow) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Open Behaviors</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1386</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Control behavior when opening forms in the Local Machine security zone (Block | Prompt | Allow)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-893-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Control behavior when opening forms in the Trusted Site security zone (Block | Prompt | Allow)" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Control behavior when opening forms in the Trusted Site security zone (Block | Prompt | Allow) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Open Behaviors</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-893</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.76. Control behavior when opening forms in the Trusted Site security zone</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Control behavior when opening forms in the Trusted Site security zone (Block | Prompt | Allow)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1290-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Beaconing UI for forms opened in InfoPath (Never show beaconing UI | Always show beaconing UI | Show UI if Form Template is from Internet Zone)" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Beaconing UI for forms opened in InfoPath (Never show beaconing UI | Always show beaconing UI | Show UI if Form Template is from Internet Zone) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1290</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.26. Beaconing UI for forms opened in InfoPath</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Beaconing UI for forms opened in InfoPath (Never show beaconing UI | Always show beaconing UI | Show UI if Form Template is from Internet Zone)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1381-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Beaconing UI for forms opened in InfoPath Editor ActiveX (Never show beaconing UI | Always show beaconing UI | Show UI if Form Template is from Internet Zone)" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Beaconing UI for forms opened in InfoPath Editor ActiveX (Never show beaconing UI | Always show beaconing UI | Show UI if Form Template is from Internet Zone) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1381</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.27. Beaconing UI for forms opened in InfoPath Editor ActiveX</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Beaconing UI for forms opened in InfoPath Editor ActiveX (Never show beaconing UI | Always show beaconing UI | Show UI if Form Template is from Internet Zone)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1135-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable all application add-ins" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Trust Center\Disable all application add-ins </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1135</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.87. Disable all application add-ins</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Trust Center\Disable all application add-ins</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1157-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Require that application add-ins are signed by Trusted Publisher" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Trust Center\Require that application add-ins are signed by Trusted Publisher </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1157</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.200. Require that application add-ins are signed by Trusted Publisher</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Trust Center\Require that application add-ins are signed by Trusted Publisher</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1434-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable Trust Bar Notification for unsigned application add-ins" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Trust Center\Disable Trust Bar Notification for unsigned application add-ins </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1434</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.120. Disable Trust Bar Notification for unsigned application add-ins</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Security\Trust Center\Disable Trust Bar Notification for unsigned application add-ins</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1315-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Control behavior when opening InfoPath e-mail forms containing code or script (Run without prompting | Prompt before running | Never run)" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Control behavior when opening InfoPath e-mail forms containing code or script (Run without prompting | Prompt before running | Never run) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1315</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.77. Control behavior when opening InfoPath e-mail forms containing code or script</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Control behavior when opening InfoPath e-mail forms containing code or script (Run without prompting | Prompt before running | Never run)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1210-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable sending form template with e-mail forms" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Disable sending form template with e-mail forms </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Deployment</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1210</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.112. Disable sending form template with e-mail forms</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Disable sending form template with e-mail forms</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1236-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable dynamic caching of the form template in InfoPath e-mail forms" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Disable dynamic caching of the form template in InfoPath e-mail forms </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Deployment</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1236</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.97. Disable dynamic caching of the form template in InfoPath e-mail forms</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Disable dynamic caching of the form template in InfoPath e-mail forms</reference>
      </references>
    </cce>
    <cce cce_id='CCE-884-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable sending InfoPath 2003 Forms as e-mail forms" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Disable sending InfoPath 2003 Forms as e-mail forms </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-884</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.113. Disable sending InfoPath 2003 Forms as e-mail forms</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Disable sending InfoPath 2003 Forms as e-mail forms</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1518-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable e-mail forms running in restricted security level" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Disable e-mail forms running in restricted security level </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1518</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.101. Disable e-mail forms running in restricted security level</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Disable e-mail forms running in restricted security level</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1170-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable e-mail forms from the Internet security zone" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Disable e-mail forms from the Internet security zone </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1170</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.99. Disable e-mail forms from the Internet security zone</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Disable e-mail forms from the Internet security zone</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1316-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable e-mail forms from the Intranet security zone" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Disable e-mail forms from the Intranet security zone </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1316</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.100. Disable e-mail forms from the Intranet security zone</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Disable e-mail forms from the Intranet security zone</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1567-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable e-mail forms from the Full Trust security zone" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Disable e-mail forms from the Full Trust security zone </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1567</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.98. Disable e-mail forms from the Full Trust security zone</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Disable e-mail forms from the Full Trust security zone</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1265-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable InfoPath e-mail forms in Outlook" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Disable InfoPath e-mail forms in Outlook </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1265</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.106. Disable InfoPath e-mail forms in Outlook</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Disable items in user interface\Disable InfoPath e-mail forms in Outlook</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1538-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Information Rights Management" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Restricted Features\Information Rights Management </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Designer\RestrictedFeatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1538</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.163. Information Rights Management</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Restricted Features\Information Rights Management</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1564-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Custom code" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Restricted Features\Custom code </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Designer\RestrictedFeatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1564</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.79. Custom code</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Restricted Features\Custom code</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1212-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Email Forms Beaconing UI (Never show UI | Always show UI | Show UI if XSN is in Internet Zone)" setting should be configured correctly for InfoPath 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Miscellaneous\Email Forms Beaconing UI (Never show UI | Always show UI | Show UI if XSN is in Internet Zone) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1212</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.147. Email Forms Beaconing UI</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office InfoPath 2007\Miscellaneous\Email Forms Beaconing UI (Never show UI | Always show UI | Show UI if XSN is in Internet Zone)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1344-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable user customization of Quick Access Toolbar via UI" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable user customization of Quick Access Toolbar via UI </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1344</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.122. Disable user customization of Quick Access Toolbar via UI</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable user customization of Quick Access Toolbar via UI</reference>
      </references>
    </cce>
    <cce cce_id='CCE-723-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable user customization of Quick Access Toolbar via UI - Disallow in Word" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable user customization of Quick Access Toolbar via UI - Disallow in Word </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-723</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.122. Disable user customization of Quick Access Toolbar via UI</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable user customization of Quick Access Toolbar via UI - Disallow in Word</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1384-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable user customization of Quick Access Toolbar via UI - Disallow in Excel" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable user customization of Quick Access Toolbar via UI - Disallow in Excel </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1384</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.122. Disable user customization of Quick Access Toolbar via UI</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable user customization of Quick Access Toolbar via UI - Disallow in Excel</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1159-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable user customization of Quick Access Toolbar via UI - Disallow in PowerPoint" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable user customization of Quick Access Toolbar via UI - Disallow in PowerPoint </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1159</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.122. Disable user customization of Quick Access Toolbar via UI</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable user customization of Quick Access Toolbar via UI - Disallow in PowerPoint</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1146-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable user customization of Quick Access Toolbar via UI - Disallow in Access" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable user customization of Quick Access Toolbar via UI - Disallow in Access </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1146</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.122. Disable user customization of Quick Access Toolbar via UI</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable user customization of Quick Access Toolbar via UI - Disallow in Access</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1542-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable user customization of Quick Access Toolbar via UI - Disallow in Outlook" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable user customization of Quick Access Toolbar via UI - Disallow in Outlook </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1542</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.122. Disable user customization of Quick Access Toolbar via UI</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable user customization of Quick Access Toolbar via UI - Disallow in Outlook</reference>
      </references>
    </cce>
    <cce cce_id='CCE-582-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable all user customization of Quick Access Toolbar" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable all user customization of Quick Access Toolbar </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-582</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.90. Disable all user customization of Quick Access Toolbar</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable all user customization of Quick Access Toolbar</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1291-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable all user customization of Quick Access Toolbar - Disallow in Word" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable all user customization of Quick Access Toolbar - Disallow in Word </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1291</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.90. Disable all user customization of Quick Access Toolbar</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable all user customization of Quick Access Toolbar - Disallow in Word</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1326-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable all user customization of Quick Access Toolbar - Disallow in Excel" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable all user customization of Quick Access Toolbar - Disallow in Excel </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1326</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.90. Disable all user customization of Quick Access Toolbar</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable all user customization of Quick Access Toolbar - Disallow in Excel</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1330-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable all user customization of Quick Access Toolbar - Disallow in PowerPoint" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable all user customization of Quick Access Toolbar - Disallow in PowerPoint </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1330</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.90. Disable all user customization of Quick Access Toolbar</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable all user customization of Quick Access Toolbar - Disallow in PowerPoint</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1335-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable all user customization of Quick Access Toolbar - Disallow in Access" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable all user customization of Quick Access Toolbar - Disallow in Access </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1335</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.90. Disable all user customization of Quick Access Toolbar</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable all user customization of Quick Access Toolbar - Disallow in Access</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1229-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable all user customization of Quick Access Toolbar - Disallow in Outlook" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable all user customization of Quick Access Toolbar - Disallow in Outlook </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1229</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.90. Disable all user customization of Quick Access Toolbar</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable all user customization of Quick Access Toolbar - Disallow in Outlook</reference>
      </references>
    </cce>
    <cce cce_id='CCE-630-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable UI extending from documents and templates" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable UI extending from documents and templates </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-630</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.121. Disable UI extending from documents and templates</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable UI extending from documents and templates</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1154-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable UI extending from documents and templates - Disallow in Word" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable UI extending from documents and templates - Disallow in Word </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1154</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.121. Disable UI extending from documents and templates</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable UI extending from documents and templates - Disallow in Word</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1410-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable UI extending from documents and templates - Disallow in Excel" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable UI extending from documents and templates - Disallow in Excel </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1410</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.121. Disable UI extending from documents and templates</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable UI extending from documents and templates - Disallow in Excel</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1432-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable UI extending from documents and templates - Disallow in PowerPoint" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable UI extending from documents and templates - Disallow in PowerPoint </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1432</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.121. Disable UI extending from documents and templates</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable UI extending from documents and templates - Disallow in PowerPoint</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1198-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable UI extending from documents and templates - Disallow in Access" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable UI extending from documents and templates - Disallow in Access </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1198</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.121. Disable UI extending from documents and templates</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable UI extending from documents and templates - Disallow in Access</reference>
      </references>
    </cce>
    <cce cce_id='CCE-929-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable UI extending from documents and templates - Disallow in Outlook" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable UI extending from documents and templates - Disallow in Outlook </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-929</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.121. Disable UI extending from documents and templates</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Global Options\Customize\Disable UI extending from documents and templates - Disallow in Outlook</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1074-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Recognize smart tags in Excel" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | AutoCorrect Options... (Excel, Word, PowerPoint and Access)\Recognize smart tags in Excel </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1074</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.194. Recognize smart tags in Excel</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | AutoCorrect Options... (Excel, Word, PowerPoint and Access)\Recognize smart tags in Excel</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1458-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable Clip Art and Media downloads from the client and from Office Online website" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | Options | General | Web Options...\Disable Clip Art and Media downloads from the client and from Office Online website </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1458</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.93. Disable Clip Art and Media downloads from the client and from Office Online website</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | Options | General | Web Options...\Disable Clip Art and Media downloads from the client and from Office Online website</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1233-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable template downloads from the client and from Office Online website" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | Options | General | Web Options...\Disable template downloads from the client and from Office Online website </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1233</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.117. Disable template downloads from the client and from Office Online website</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | Options | General | Web Options...\Disable template downloads from the client and from Office Online website</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1379-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable access to updates, add-ins, and patches on the Office Online website" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | Options | General | Web Options...\Disable access to updates, add-ins, and patches on the Office Online website </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1379</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.85. Disable access to updates, add-ins, and patches on the Office Online website</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | Options | General | Web Options...\Disable access to updates, add-ins, and patches on the Office Online website</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO177 - Office Rule ID: SV-18714r3_rule Vuln ID: V-17588: Disable access to updates, add-ins, and patches on the Office Online Website - Office.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1401-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Prevents users from uploading document templates to the Office Online community." setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | Options | General | Web Options...\Prevents users from uploading document templates to the Office Online community. </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1401</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.188. Prevents users from uploading document templates to the Office Online community</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | Options | General | Web Options...\Prevents users from uploading document templates to the Office Online community.</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO178 - Office Rule ID: SV-18972r3_rule Vuln ID: V-17767: Prevent upload of document templates to Office Online.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1528-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable training practice downloads from the Office Online website" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | Options | General | Web Options...\Disable training practice downloads from the Office Online website </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1528</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.119. Disable training practice downloads from the Office Online website</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | Options | General | Web Options...\Disable training practice downloads from the Office Online website</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1533-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable customer-submitted templates downloads from Office Online" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | Options | General | Web Options...\Disable customer-submitted templates downloads from Office Online </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1533</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.95. Disable customer-submitted templates downloads from Office Online</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | Options | General | Web Options...\Disable customer-submitted templates downloads from Office Online</reference>
      </references>
    </cce>
    <cce cce_id='CCE-646-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Open Office documents as read/write while browsing" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | Options | General | Web Options...\Files\Open Office documents as read/write while browsing </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-646</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.180. Open Office documents as read/write while browsing</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | Options | General | Web Options...\Files\Open Office documents as read/write while browsing</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO179 - Office Rule ID: SV-18956r3_rule Vuln ID: V-17759: Disable "Open documents as Read Write when browsing" feature.  - Office</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1438-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Rely on VML for displaying graphics in browsers" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | Options | General | Web Options...\Browsers\Rely on VML for displaying graphics in browsers </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1438</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.195. Rely on VML for displaying graphics in browsers</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | Options | General | Web Options...\Browsers\Rely on VML for displaying graphics in browsers</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO180 - Office Rule ID: SV-18983r3_rule Vuln ID: V-17773: Do Not rely on Vector markup Language (VML) for displaying graphics in browsers.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-711-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Allow PNG as an output format" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | Options | General | Web Options...\Browsers\Allow PNG as an output format </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-711</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.9. Allow PNG as an output format</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | Options | General | Web Options...\Browsers\Allow PNG as an output format</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO181 - Office Rule ID: SV-18661r3_rule Vuln ID: V-17561: Do not allow choice of output to include PNG (Portable Network Graphics)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1292-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Improve Proofing Tools" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | Options | Spelling\Proofing Data Collection\Improve Proofing Tools </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\PTWatson</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1292</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.160. Improve Proofing Tools</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Tools | Options | Spelling\Proofing Data Collection\Improve Proofing Tools</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO182 - Office Rule ID: SV-18770r3_rule Vuln ID: V-17627: Configure the Help Improve Proofing Tools feature for Office.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1615-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable Opt-in Wizard on first run" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Classic Administrative Templates\Microsoft Office 2007\Privacy \Trust Center\Disable Opt-in Wizard on first run </technical_mechanism>
        <technical_mechanism>(2)  HKEY_CURRENT_USER\Software\Policies\Microsoft\Office\12.0\Common\QMEnable</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1615</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.110. Disable Opt-in Wizard on first run</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Privacy\Trust Center\Disable Opt-in Wizard on first run</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO183 - Office Rule ID: SV-18824r1_rule Vuln ID: V-17664: Disable the Opt-In Wizard that enables first time users to opt into Internet–based Microsoft services.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1191-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Microsoft Office Online" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Help\Microsoft Office Online </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1191</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Help\Microsoft Office Online</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1587-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable Password Caching" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Disable Password Caching </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1587</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Disable Password Caching</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1486-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable all Trust Bar notifications for security issues" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Disable all Trust Bar notifications for security issues </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\TrustCenter</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1486</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.88. Disable all Trust Bar notifications for security issues</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Disable all Trust Bar notifications for security issues</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO186 - Office Rule ID: SV-18717r3_rule Vuln ID: V-17590: Disable the ability for users to Disable Trust Bar notifications for Security messages - Office</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1508-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Protect document metadata for rights managed Office Open XML Files" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Protect document metadata for rights managed Office Open XML Files </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1508</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.191. Protect document metadata for rights managed Office Open XML Files</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Protect document metadata for rights managed Office Open XML Files</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO187 - Office Rule ID: SV-18976r3_rule Vuln ID: V-17769: Protect document metadata for rights managed Office Open XML fiiles - Office</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1640-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Protect document metadata for password protected files." setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Protect document metadata for password protected files. </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1640</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.190. Protect document metadata for password protected files</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Protect document metadata for password protected files.</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO188 - Office Rule ID: SV-18974r3_rule Vuln ID: V-17768: Protect document metadata for password protected files - Office</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1539-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Encryption type for password protected Office Open XML files" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Encryption type for password protected Office Open XML files </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1539</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.153. Encryption type for password protected Office Open XML files</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Encryption type for password protected Office Open XML files</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO189 - Office 2007 Rule ID: SV-18758r5_rule Vuln ID: V-17619: Encryption type for password protected Open XML files - Office</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1561-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Encryption type for password protected Office 97-2003 files" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Encryption type for password protected Office 97-2003 files </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1561</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.152. Encryption type for password protected Office 97-2003 files</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Encryption type for password protected Office 97-2003 files</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO190 - Office 2007 Rule ID: SV-18755r6_rule Vuln ID: V-17617: Set encryption type for password protected Office 97 thru Office 2003 files - Office</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1068-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Load Controls in Forms3 (1 | 2 | 3 | 4)" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Load Controls in Forms3 (1 | 2 | 3 | 4) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\VBA\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1068</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.168. Load Controls in Forms3</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Load Controls in Forms3 (1 | 2 | 3 | 4)</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO192 - Office  Rule ID: SV-18939r3_rule Vuln ID: V-17750: Enable Load controls in forms3 - Office</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1574-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Automation Security (Disable macros by default | Use application macro security level | Macros enabled)" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>2007: (1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Automation Security (Disable macros by default | Use application macro security level | Macros enabled) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\Common\Security 2003: (1) Computer Configuration\Administrative Templates\Microsoft Office 2003\Security Settings\Automation Security </technical_mechanism>
        <technical_mechanism>(2)  HKLM\Software\Policies\Microsoft\Office\11.0\Common\Security - AutomationSecurity</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1574</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.24. Automation Security</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Automation Security (Disable macros by default | Use application macro security level | Macros enabled)</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO193 - Office Rule ID: SV-18924r3_rule Vuln ID: V-17741: Enable Automation Security to enforce macro level security in Office documents</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1239-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Prevent Word and Excel from loading managed code extensions" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Prevent Word and Excel from loading managed code extensions </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\Common\Smart Tag</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1239</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Prevent Word and Excel from loading managed code extensions</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1623-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable hyperlink warnings" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Disable hyperlink warnings </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1623</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.103. Disable hyperlink warnings</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Disable hyperlink warnings</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO194 - Office Rule ID: SV-18814r3_rule Vuln ID: V-17659: Configure the "disable hyperlink warnings" for Office to Disable.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1083-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable password to open UI" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Disable password to open UI </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1083</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.111. Disable password to open UI</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Disable password to open UI</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO195 - Office Rule ID: SV-18826r3_rule Vuln ID: V-17665: Configure the "Disable Password to Open UI" for password secured documents.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1343-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Download Office Controls" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Download Office Controls </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1343</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Download Office Controls</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1242-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable All ActiveX" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Disable All ActiveX </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\Common\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1242</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.86. Disable All ActiveX</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Disable All ActiveX</reference>
      </references>
    </cce>
    <cce cce_id='CCE-770-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Allow mix of policy and user locations" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Trust Center\Allow mix of policy and user locations </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Security\Trusted Locations</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-770</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.8. Allow mix of policy and user locations</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Security Settings\Trust Center\Allow mix of policy and user locations</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO196 - Office Rule ID: SV-18659r3_rule Vuln ID: V-17560: Do not allow a mix of policy and user locations for Office Products.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-903-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable Smart Document's use of manifests" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Smart Documents (Word, Excel)\Disable Smart Document's use of manifests </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\Common\Smart Tag</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-903</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.116. Disable Smart Document's use of manifests</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Smart Documents (Word, Excel)\Disable Smart Document's use of manifests</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO197 - Office Rule ID: SV-18834r3_rule Vuln ID: V-17669: Disable Smart Documents use of Manifests in Office</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1555-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Completely disable the Smart Documents feature in Word and Excel" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Smart Documents (Word, Excel)\Completely disable the Smart Documents feature in Word and Excel </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\Common\Smart Tag</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1555</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Smart Documents (Word, Excel)\Completely disable the Smart Documents feature in Word and Excel</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1061-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable Internet Fax feature" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Services\Fax\Disable Internet Fax feature </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Services\Fax</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1061</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.107. Disable Internet Fax feature</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Services\Fax\Disable Internet Fax feature</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO198 - Office Rule ID: SV-18818r3_rule Vuln ID: V-17661: Disable the ability for Office users to use the Internet Fax Feature.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1603-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Prevent users from changing permissions on rights managed content" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Manage Restricted Permissions\Prevent users from changing permissions on rights managed content </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\DRM</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1603</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.187. Prevent users from changing permissions on rights managed content</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Manage Restricted Permissions\Prevent users from changing permissions on rights managed content</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO199 - Office Rule ID: SV-18968r3_rule Vuln ID: V-17765: Prevent permissions change on 'rights managed' content - Office</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1612-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Allow users with earlier versions of Office to read with browsers..." setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Manage Restricted Permissions\Allow users with earlier versions of Office to read with browsers... </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\DRM</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1612</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.13. Allow users with earlier versions of Office to read with browsers…</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Manage Restricted Permissions\Allow users with earlier versions of Office to read with browsers...</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO200 - Office 2007 Rule ID: SV-18782r3_rule Vuln ID: V-17583: Allow users with earlier versions of Office to read with browsers - System</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1493-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Always require users to connect to verify permission" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Manage Restricted Permissions\Always require users to connect to verify permission </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\DRM</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1493</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.15. Always require users to connect to verify permission</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Manage Restricted Permissions\Always require users to connect to verify permission</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO201 - Office Rule ID: SV-18906r3_rule Vuln ID: V-17731: Always require users to connect to verify permissions - Office.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1409-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Always expand groups in Office when restricting permission for documents" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Manage Restricted Permissions\Always expand groups in Office when restricting permission for documents </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\DRM\AutoExpandDls</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1409</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.14. Always expand groups in Office when restricting permission for documents</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Manage Restricted Permissions\Always expand groups in Office when restricting permission for documents</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1589-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Never allow users to specify groups when restricting permission for documents" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Manage Restricted Permissions\Never allow users to specify groups when restricting permission for documents </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\DRM</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1589</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.177. Never allow users to specify groups when restricting permission for documents</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Manage Restricted Permissions\Never allow users to specify groups when restricting permission for documents</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1237-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable Microsoft Passport service for content with restricted permission" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Manage Restricted Permissions\Disable Microsoft Passport service for content with restricted permission </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\DRM</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1237</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.108. Disable Microsoft Passport service for content with restricted permission</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Manage Restricted Permissions\Disable Microsoft Passport service for content with restricted permission</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO202 - Office Rule ID: SV-18820r3_rule Vuln ID: V-17662: Disable Microsoft passport Service for content with restricted permissions - Office.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1404-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Do not allow users to upgrade Information Rights Management configuration" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Manage Restricted Permissions\Do not allow users to upgrade Information Rights Management configuration </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\DRM</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1404</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Manage Restricted Permissions\Do not allow users to upgrade Information Rights Management configuration</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1396-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Key Usage Filtering" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Signing\Key Usage Filtering </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\General</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1396</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.166. Key Usage Filtering</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Signing\Key Usage Filtering</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1167-6' platform='office2k7' modified='2013-02-11'>
      <description>The "EKU filtering" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Signing\EKU filtering </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Signatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1167</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.146. EKU filtering</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Signing\EKU filtering</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1585-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Legacy format signatures" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Signing\Legacy format signatures </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Signatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1585</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.167. Legacy format signatures</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Signing\Legacy format signatures</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO203 - Office Rule ID: SV-18937r3_rule Vuln ID: V-17749: Legacy format signatures should be enabled - Office</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1572-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Suppress Office Signing Providers (Enable Western and East Asian | Suppress default Western | Suppress default East Asian | Suppress both Western and East Asian)" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Signing\Suppress Office Signing Providers (Enable Western and East Asian | Suppress default Western | Suppress default East Asian | Suppress both Western and East Asian) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Signatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1572</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.223. Suppress Office Signing Providers</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Signing\Suppress Office Signing Providers (Enable Western and East Asian | Suppress default Western | Suppress default East Asian | Suppress both Western and East Asian)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1220-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Suppress external signature services menu item" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Signing\Suppress external signature services menu item </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Signatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1220</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.222. Suppress external signature services menu item</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Signing\Suppress external signature services menu item</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO204 - Office Rule ID: SV-19036r3_rule Vuln ID: V-17805: Enable the feature to suppress external Signature Services Menu for Office.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1634-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable Check For Solutions" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Office Diagnostics\Disable Check For Solutions </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\Common\OffDiag</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1634</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.92. Disable Check For Solutions</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Office Diagnostics\Disable Check For Solutions</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO205 - Office 2007 Rule ID: SV-18802r3_rule Vuln ID: V-17653: Enable the "Disable Check for Solutions" in Office.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1643-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable inclusion of document properties in PDF and XPS output" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Microsoft Save As PDF and XPS add-ins\Disable inclusion of document properties in PDF and XPS output </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\FixedFormat</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1643</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.105. Disable inclusion of document properties in PDF and XPS output</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Microsoft Save As PDF and XPS add-ins\Disable inclusion of document properties in PDF and XPS output</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO206 - Office  Rule ID: SV-18816r3_rule Vuln ID: V-17660: Disable inclusion of document properties for PDF and XPS output - Office.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1546-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable Document Information Panel" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Document Information Panel\Disable Document Information Panel </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\DocumentInformationPanel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1546</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.96. Disable Document Information Panel</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Document Information Panel\Disable Document Information Panel</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1505-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Document Information Panel Beaconing UI (Never show UI | Always show UI | Show UI if XSN is in Internet Zone)" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Document Information Panel\Document Information Panel Beaconing UI (Never show UI | Always show UI | Show UI if XSN is in Internet Zone) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\DocumentInformationPanel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1505</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.144. Document Information Panel Beaconing UI</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Document Information Panel\Document Information Panel Beaconing UI (Never show UI | Always show UI | Show UI if XSN is in Internet Zone)</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO207 - Office 2007 Rule ID: SV-18740r3_rule Vuln ID: V-17605: Always show Document Information Panel Beaconing UI - Office</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1545-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable the Office client from polling the Office server for published links" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Server Settings\Disable the Office client from polling the Office server for published links </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Portal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1545</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.118. Disable the Office client from polling the Office server for published links</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Server Settings\Disable the Office client from polling the Office server for published links</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO208 - Office Rule ID: SV-18836r3_rule Vuln ID: V-17670: Disable the Office client from polling the Sharepoint server for published links.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1549-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of pre-release versions of file formats new to Word 2007 through the Compatibility Pack for the 2007 Office system and Word 2007 Open XML/Word 97-2003 Format Converter" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Office 2007 Converters\Block opening of pre-release versions of file formats new to Word 2007 through the Compatibility Pack for the 2007 Office system and Word 2007 Open XML/Word 97-2003 Format Converter </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1549</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.44. Block opening of pre-release versions of file formats new to Word 2007 through the Compatibility Pack for the 2007 Office system and Word 2007 Open XML/Word 97-2003 Format Converter</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Office 2007 Converters\Block opening of pre-release versions of file formats new to Word 2007 through the Compatibility Pack for the 2007 Office system and Word 2007 Open XML/Word 97-2003 Format Converter</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1431-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of pre-release versions of file formats new to Excel 2007 through the Compatibility Pack for the 2007 Office system and Excel 2007 Converter" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Office 2007 Converters\Block opening of pre-release versions of file formats new to Excel 2007 through the Compatibility Pack for the 2007 Office system and Excel 2007 Converter </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Excel\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1431</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.40. Block opening of pre-release versions of file formats new to Excel 2007 through the Compatibility Pack for the 2007 Office system and Excel 2007 Converter</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Office 2007 Converters\Block opening of pre-release versions of file formats new to Excel 2007 through the Compatibility Pack for the 2007 Office system and Excel 2007 Converter</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1594-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of pre-release versions of file formats new to PowerPoint 2007 through the Compatibility Pack for the 2007 Office system and PowerPoint 2007 Converter" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Office 2007 Converters\Block opening of pre-release versions of file formats new to PowerPoint 2007 through the Compatibility Pack for the 2007 Office system and PowerPoint 2007 Converter </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1594</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.42. Block opening of pre-release versions of file formats new to PowerPoint 2007 through the Compatibility Pack for the 2007 Office system and PowerPoint 2007 Converter</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Office 2007 Converters\Block opening of pre-release versions of file formats new to PowerPoint 2007 through the Compatibility Pack for the 2007 Office system and PowerPoint 2007 Converter</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1241-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Control Blogging (Enabled | Only SharePoint blogs allowed | All blogging disabled)" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Miscellaneous\Control Blogging (Enabled | Only SharePoint blogs allowed | All blogging disabled) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Blog</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1241</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.78. Control blogging</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Miscellaneous\Control Blogging (Enabled | Only SharePoint blogs allowed | All blogging disabled)</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO212 - Office Rule ID: SV-18701r3_rule Vuln ID: V-17581: Control Blogging entries created from inside Office products.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1607-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Enable Smart Resume" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Miscellaneous\Enable Smart Resume </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Restore Workspace</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1607</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Miscellaneous\Enable Smart Resume</reference>
      </references>
    </cce>
    <cce cce_id='CCE-752-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Do not upload media files" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Miscellaneous\Do not upload media files </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-752</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Miscellaneous\Do not upload media files</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1166-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable hyperlinks to web templates in File | New and task panes" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Miscellaneous\Disable hyperlinks to web templates in File | New and task panes </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\Internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1166</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.104. Disable hyperlinks to web templates from the client and from Office Online website</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Miscellaneous\Disable hyperlinks to web templates in File | New and task panes</reference>
      </references>
    </cce>
    <cce cce_id='CCE-654-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Prevent access to Web-based file storage" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2007 system\Miscellaneous\Prevent access to Web-based file storage </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\WebServices</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-654</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office 2007 system\Miscellaneous\Prevent access to Web-based file storage</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1192-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Do not allow attachment previewing in Outlook" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\E-mail Options\Do not allow attachment previewing in Outlook </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1192</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.128. Do not allow attachment previewing in Outlook</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\E-mail Options\Do not allow attachment previewing in Outlook</reference>
      </references>
    </cce>
    <cce cce_id='CCE-791-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Read e-mail as plain text" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\E-mail Options\Read e-mail as plain text </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-791</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.192. Read e-mail as plain text</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\E-mail Options\Read e-mail as plain text</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1456-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Read signed e-mail as plain text" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\E-mail Options\Read signed e-mail as plain text </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1456</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.193. Read signed e-mail as plain text</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\E-mail Options\Read signed e-mail as plain text</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1478-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Prevent publishing to Office Online" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\Calendar Options\Microsoft Office Online Sharing ServicePrevent publishing to Office Online </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\PubCal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1478</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.185. Prevent publishing to Office Online</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\Calendar Options\Microsoft Office Online Sharing ServicePrevent publishing to Office Online</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1368-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Prevent publishing to a DAV server" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\Calendar Options\Microsoft Office Online Sharing ServicePrevent publishing to a DAV server </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\PubCal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1368</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.184. Prevent publishing to a DAV server</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\Calendar Options\Microsoft Office Online Sharing ServicePrevent publishing to a DAV server</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1641-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Restrict level of calendar details users can publish (All options are available | Disables 'Full details' | Disables 'Full details' and 'Limited details')" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\Calendar Options\Microsoft Office Online Sharing ServiceRestrict level of calendar details users can publish (All options are available | Disables 'Full details' | Disables 'Full details' and 'Limited details') </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\PubCal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1641</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.202. Restrict level of calendar details users can publish</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\Calendar Options\Microsoft Office Online Sharing ServiceRestrict level of calendar details users can publish (All options are available | Disables 'Full details' | Disables 'Full details' and 'Limited details')</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1266-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Access to published calendars" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\Calendar Options\Microsoft Office Online Sharing ServiceAccess to published calendars </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\PubCal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1266</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.1. Access to published calendars</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\Calendar Options\Microsoft Office Online Sharing ServiceAccess to published calendars</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1399-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Restrict upload method" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\Calendar Options\Microsoft Office Online Sharing ServiceRestrict upload method </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\PubCal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1399</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.203. Restrict upload method</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\Calendar Options\Microsoft Office Online Sharing ServiceRestrict upload method</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1187-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Hide Junk Mail UI" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\Junk E-mail\Hide Junk Mail UI </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1187</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.158. Hide Junk Mail UI</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\Junk E-mail\Hide Junk Mail UI</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1588-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Junk E-mail protection level (No Protection, Low, High, Trusted Lists Only)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\Junk E-mail\Junk E-mail protection level (No Protection, Low, High, Trusted Lists Only) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1588</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.165. Junk E-mail protection level</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\Junk E-mail\Junk E-mail protection level (No Protection, Low, High, Trusted Lists Only)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1117-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Trust E-mail from Contacts" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\Junk E-mail\Trust E-mail from Contacts </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1117</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.226. Trust E-mail from Contacts</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\Junk E-mail\Trust E-mail from Contacts</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1130-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Add e-mail recipients to users' Safe Senders Lists" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\Junk E-mail\Add e-mail recipients to users' Safe Senders Lists </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1130</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.4. Add e-mail recipients to users' Safe Senders Lists</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Preferences\Junk E-mail\Add e-mail recipients to users' Safe Senders Lists</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1093-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Dial-up options" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Mail Setup\Dial-up options </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1093</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.84. Dial-up options</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Mail Setup\Dial-up options</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1599-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Dial-up options - Warn before switching dial-up connection" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Mail Setup\Dial-up options - Warn before switching dial-up connection </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1599</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.84. Dial-up options</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Mail Setup\Dial-up options - Warn before switching dial-up connection</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1621-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Dial-up options - Hang up when finished sending, receiving, or updating" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Mail Setup\Dial-up options - Hang up when finished sending, receiving, or updating </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1621</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.84. Dial-up options</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Mail Setup\Dial-up options - Hang up when finished sending, receiving, or updating</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1269-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Dial-up options - Automatically dial during a background Send/Receive" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Mail Setup\Dial-up options - Automatically dial during a background Send/Receive </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1269</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.84. Dial-up options</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Mail Setup\Dial-up options - Automatically dial during a background Send/Receive</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1419-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Do not allow creating, replying, or forwarding signatures for e-mail messages" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Mail Format\Do not allow creating, replying, or forwarding signatures for e-mail messages </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\MailSettings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1419</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.129. Do not allow creating, replying, or forwarding signatures for e-mail messages</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Mail Format\Do not allow creating, replying, or forwarding signatures for e-mail messages</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1551-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Send copy of pictures with HTML messages instead of reference to Internet location" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Mail Format\Internet Formatting\Send copy of pictures with HTML messages instead of reference to Internet location </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1551</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Mail Format\Internet Formatting\Send copy of pictures with HTML messages instead of reference to Internet location</reference>
      </references>
    </cce>
    <cce cce_id='CCE-655-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Outlook Rich Text options (Convert to HTML | Convert to Plain Text format | Send Using Outlook Rich Text format)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Mail Format\Internet Formatting\Outlook Rich Text options (Convert to HTML | Convert to Plain Text format | Send Using Outlook Rich Text format) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-655</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.181. Outlook Rich Text options</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Mail Format\Internet Formatting\Outlook Rich Text options (Convert to HTML | Convert to Plain Text format | Send Using Outlook Rich Text format)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1592-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Plain text options" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Mail Format\Internet Formatting\Plain text options </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1592</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.183. Plain text options</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Mail Format\Internet Formatting\Plain text options</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1614-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Plain text options - Encode attachments in UUENCODE format when sending a plain text message" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Mail Format\Internet Formatting\Plain text options - Encode attachments in UUENCODE format when sending a plain text message </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1614</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.183. Plain text options</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Mail Format\Internet Formatting\Plain text options - Encode attachments in UUENCODE format when sending a plain text message</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1526-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Set message format (HTML | Rich Text | Plain Text)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Mail Format\Internet Formatting\Message FormatSet message format (HTML | Rich Text | Plain Text) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1526</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.217. Set message format</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Mail Format\Internet Formatting\Message FormatSet message format (HTML | Rich Text | Plain Text)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1111-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Make Outlook the default program for E-mail, Contacts, and Calendar" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Other\Make Outlook the default program for E-mail, Contacts, and Calendar </technical_mechanism>
        <technical_mechanism>(2)  software\policies\microsoft\office\12.0\outlook\options\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1111</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.171. Make Outlook the default program for E-mail, Contacts, and Calendar</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Other\Make Outlook the default program for E-mail, Contacts, and Calendar</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1494-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Do not allow folders in non-default stores to be set as folder home pages" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Other\Advanced\Do not allow folders in non-default stores to be set as folder home pages </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1494</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.130. Do not allow folders in non-default stores to be set as folder home pages</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Other\Advanced\Do not allow folders in non-default stores to be set as folder home pages</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1287-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Use Unicode format when dragging e-mail message to file system" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Other\Advanced\Use Unicode format when dragging e-mail message to file system </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\General</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1287</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.233. Use Unicode format when dragging e-mail message to file system</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Other\Advanced\Use Unicode format when dragging e-mail message to file system</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1529-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Do not allow Outlook object model scripts to run for shared folders" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Other\Advanced\Do not allow Outlook object model scripts to run for shared folders </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1529</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.132. Do not allow Outlook object model scripts to run for shared folders</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Other\Advanced\Do not allow Outlook object model scripts to run for shared folders</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1560-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Do not allow Outlook object model scripts to run for public folders" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Other\Advanced\Do not allow Outlook object model scripts to run for public folders </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1560</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.131. Do not allow Outlook object model scripts to run for public folders</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Other\Advanced\Do not allow Outlook object model scripts to run for public folders</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1596-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Set maximum level of online status on a person name (Do not allow | Allow everywhere except To and CC field | Allow everywhere)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Other\Person Names\Set maximum level of online status on a person name (Do not allow | Allow everywhere except To and CC field | Allow everywhere) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\IM</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1596</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.216. Set maximum level of online status on a person name</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Other\Person Names\Set maximum level of online status on a person name (Do not allow | Allow everywhere except To and CC field | Allow everywhere)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1604-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Display online status on a person name (Never | Everywhere except To and CC field | Everywhere)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Other\Person Names\Display online status on a person name (Never | Everywhere except To and CC field | Everywhere) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\IM</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1604</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.126. Display online status on a person name</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Other\Person Names\Display online status on a person name (Never | Everywhere except To and CC field | Everywhere)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1648-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Turn off Enable the Person Names Smart Tag option" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Other\Person Names\Turn off Enable the Person Names Smart Tag option </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\IM</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1648</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.227. Turn off Enable the Person Names Smart Tag option</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Options...\Other\Person Names\Turn off Enable the Person Names Smart Tag option</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1516-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Outlook Security Mode (Outlook Default Security | Use Security Form from 'Outlook Security Settings' Public Folder | Use Security Form from 'Outlook 10 Security Settings' Public Folder | Use Outlook Security Group Policy)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Outlook Security Mode (Outlook Default Security | Use Security Form from 'Outlook Security Settings' Public Folder | Use Security Form from 'Outlook 10 Security Settings' Public Folder | Use Outlook Security Group Policy) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1516</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.182. Outlook Security Mode</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Outlook Security Mode (Outlook Default Security | Use Security Form from 'Outlook Security Settings' Public Folder | Use Security Form from 'Outlook 10 Security Settings' Public Folder | Use Outlook Security Group Policy)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1296-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Display Level 1 attachments" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Attachment Security\Display Level 1 attachments </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1296</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.125. Display Level 1 attachments</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Attachment Security\Display Level 1 attachments</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1388-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Allow users to demote attachments to Level 2" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Attachment Security\Allow users to demote attachments to Level 2 </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1388</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.12. Allow users to demote attachments to Level 2</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Attachment Security\Allow users to demote attachments to Level 2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1652-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Do not prompt about Level 1 attachments when sending an item" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Attachment Security\Do not prompt about Level 1 attachments when sending an item </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1652</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.140. Do not prompt about Level 1 attachments when sending an item</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Attachment Security\Do not prompt about Level 1 attachments when sending an item</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1569-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Do not prompt about Level 1 attachments when closing an item" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Attachment Security\Do not prompt about Level 1 attachments when closing an item </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1569</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.139. Do not prompt about Level 1 attachments when closing an item</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Attachment Security\Do not prompt about Level 1 attachments when closing an item</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1459-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Allow in-place activation of embedded OLE objects" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Attachment Security\Allow in-place activation of embedded OLE objects </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1459</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Attachment Security\Allow in-place activation of embedded OLE objects</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1608-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Display OLE package objects" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Attachment Security\Display OLE package objects </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1608</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Attachment Security\Display OLE package objects</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1617-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Add file extensions to block as Level 1" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Attachment Security\Add file extensions to block as Level 1 </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1617</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.5. Add file extensions to block as Level 1</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Attachment Security\Add file extensions to block as Level 1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1631-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Remove file extensions blocked as Level 1" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Attachment Security\Remove file extensions blocked as Level 1 </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1631</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.196. Remove file extensions blocked as Level 1</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Attachment Security\Remove file extensions blocked as Level 1</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1155-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Add file extensions to block as Level 2" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Attachment Security\Add file extensions to block as Level 2 </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1155</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.6. Add file extensions to block as Level 2</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Attachment Security\Add file extensions to block as Level 2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1556-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Remove file extensions blocked as Level 2" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Attachment Security\Remove file extensions blocked as Level 2 </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1556</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.197. Remove file extensions blocked as Level 2</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Attachment Security\Remove file extensions blocked as Level 2</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1595-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Allow scripts in one-off Outlook forms" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Custom Form Security\Allow scripts in one-off Outlook forms </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1595</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.10. Allow scripts in one-off Outlook forms</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Custom Form Security\Allow scripts in one-off Outlook forms</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1436-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Set Outlook object model Custom Actions execution prompt (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Custom Form Security\Set Outlook object model Custom Actions execution prompt (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1436</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.218. Set Outlook object model Custom Actions execution prompt</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Custom Form Security\Set Outlook object model Custom Actions execution prompt (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1586-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Set control ItemProperty prompt (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security)" setting should be configured correctly</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Custom Form Security\Set control ItemProperty prompt (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1586</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.215. Set control ItemProperty prompt</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Custom Form Security\Set control ItemProperty prompt (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1590-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Configure Outlook object model prompt when sending mail (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Programmatic Security\Configure Outlook object model prompt when sending mail (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1590</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.71. Configure Outlook object model prompt when sending mail</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Programmatic Security\Configure Outlook object model prompt when sending mail (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1004-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Configure Outlook object model prompt when accessing an address book (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Programmatic Security\Configure Outlook object model prompt when accessing an address book (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1004</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.65. Configure Outlook object model prompt when accessing an address book</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Programmatic Security\Configure Outlook object model prompt when accessing an address book (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1273-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Configure Outlook object model prompt when reading address information (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Programmatic Security\Configure Outlook object model prompt when reading address information (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1273</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.69. Configure Outlook object model prompt when reading address information</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Programmatic Security\Configure Outlook object model prompt when reading address information (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1172-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Configure Outlook object model prompt when responding to meeting and task requests (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Programmatic Security\Configure Outlook object model prompt when responding to meeting and task requests (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1172</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.70. Configure Outlook object model prompt when responding to meeting and task requests</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Programmatic Security\Configure Outlook object model prompt when responding to meeting and task requests (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1568-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Configure Outlook object model prompt when executing Save As (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Programmatic Security\Configure Outlook object model prompt when executing Save As (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1568</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.68. Configure Outlook object model prompt when executing Save As</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Programmatic Security\Configure Outlook object model prompt when executing Save As (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1573-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Configure Outlook object model prompt When accessing the Formula property of a UserProperty object (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Programmatic Security\Configure Outlook object model prompt When accessing the Formula property of a UserProperty object (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1573</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.67. Configure Outlook object model prompt When accessing the Formula property of a UserProperty object</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Programmatic Security\Configure Outlook object model prompt When accessing the Formula property of a UserProperty object (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1454-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Configure Outlook object model prompt when accessing address information via UserProperties.Find (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Programmatic Security\Configure Outlook object model prompt when accessing address information via UserProperties.Find (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1454</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.66. Configure Outlook object model prompt when accessing address information via UserProperties.Find</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Programmatic Security\Configure Outlook object model prompt when accessing address information via UserProperties.Find (Prompt User | Automatically Approve | Automatically Deny | Prompt user based on computer security)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1498-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Required Certificate Authority" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Required Certificate Authority </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1498</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.201. Required Certificate Authority</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Required Certificate Authority</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1630-3' platform='office2k7' modified='2013-02-11'>
      <description>The "S/MIME interoperability with external clients: (Handle internally | Handle externally | Handle if possible)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\S/MIME interoperability with external clients: (Handle internally | Handle externally | Handle if possible) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1630</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.207. S/MIME interoperability with external clients:</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\S/MIME interoperability with external clients: (Handle internally | Handle externally | Handle if possible)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1626-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Always use Rich Text formatting in S/MIME messages" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Always use Rich Text formatting in S/MIME messages </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1626</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Always use Rich Text formatting in S/MIME messages</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1163-5' platform='office2k7' modified='2013-02-11'>
      <description>The "S/MIME password settings" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\S/MIME password settings </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Cryptography\Defaults\Provider\Microsoft Exchange Cryptographic Provider v1.0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1163</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.208. S/MIME password settings</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\S/MIME password settings</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1445-6' platform='office2k7' modified='2013-02-11'>
      <description>The "S/MIME password settings - Default S/MIME password time (minutes): (0 - 2147483647)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\S/MIME password settings - Default S/MIME password time (minutes): (0 - 2147483647) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Cryptography\Defaults\Provider\Microsoft Exchange Cryptographic Provider v1.0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1445</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.208. S/MIME password settings</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\S/MIME password settings - Default S/MIME password time (minutes): (0 - 2147483647)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1582-6' platform='office2k7' modified='2013-02-11'>
      <description>The "S/MIME password settings - Maximum S/MIME password time (minutes): (0 - 2147483647)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\S/MIME password settings - Maximum S/MIME password time (minutes): (0 - 2147483647) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Cryptography\Defaults\Provider\Microsoft Exchange Cryptographic Provider v1.0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1582</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.208. S/MIME password settings</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\S/MIME password settings - Maximum S/MIME password time (minutes): (0 - 2147483647)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1357-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Message Formats" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Message Formats </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1357</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.172. Message Formats</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Message Formats</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1132-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Message Formats - Support the following message formats: (S/MIME | Exchange | Fortezza | S/MIME and Exchange | S/MIME and Fortezza | Exchange and Fortezza | S/MIME, Exchange, and Fortezza)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Message Formats - Support the following message formats: (S/MIME | Exchange | Fortezza | S/MIME and Exchange | S/MIME and Fortezza | Exchange and Fortezza | S/MIME, Exchange, and Fortezza) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1132</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.172. Message Formats</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Message Formats - Support the following message formats: (S/MIME | Exchange | Fortezza | S/MIME and Exchange | S/MIME and Fortezza | Exchange and Fortezza | S/MIME, Exchange, and Fortezza)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1511-5' platform='office2k7' modified='2013-02-11'>
      <description>2007: The "Do not provide Continue option on Encryption warning dialog boxes" setting should be configured correctly for Outlook 2007. 2003: The "Disable Continue button on all Encryption warning dialogs" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) 2007: User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Do not provide Continue option on Encryption warning dialog boxes </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security 2003: </technical_mechanism>
        <technical_mechanism>(3) User Configuration\Administrative Templates\Microsoft Office Outlook 2003\Tools\Options\Security\Cryptography\Disable Continue button on all Encryption warning dialogs </technical_mechanism>
        <technical_mechanism>(4) HKCU\Software\Policies\Microsoft\office\11.0\outlook\Security - DisableContinue</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1511</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.142. Do not provide Continue option on Encryption warning dialog boxes</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Do not provide Continue option on Encryption warning dialog boxes</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1018-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Run in FIPS compliant mode" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Run in FIPS compliant mode </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1018</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.205. Run in FIPS compliant mode</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Run in FIPS compliant mode</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1181-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Encrypt all e-mail messages" setting should be configured correctly for Outlook 2007 and 2003.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>2007: (1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Encrypt all e-mail messages </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security 2003: (1) User Configuration\Administrative Templates\Microsoft Office Outlook 2003\Tools\Options\Security\Cryptography\Encrypt all e-mail messages </technical_mechanism>
        <technical_mechanism>(2)  HKCU\Software\Policies\Microsoft\Office\11.0\Outlook\Security - AlwaysEncrypt</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1181</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.151. Encrypt all e-mail messages</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Encrypt all e-mail messages</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1639-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Sign all e-mail messages" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Sign all e-mail messages </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1639</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.219. Sign all e-mail messages</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Sign all e-mail messages</reference>
      </references>
    </cce>
    <cce cce_id='CCE-677-5' platform='office2k7' modified='2013-02-11'>
      <description>The "URL for S/MIME certificates" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\URL for S/MIME certificates </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-677</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.232. URL for S/MIME certificates</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\URL for S/MIME certificates</reference>
      </references>
    </cce>
    <cce cce_id='CCE-687-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Ensure all S/MIME signed messages have a label" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Ensure all S/MIME signed messages have a label </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-687</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.154. Ensure all S/MIME signed messages have a label</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Ensure all S/MIME signed messages have a label</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1613-9' platform='office2k7' modified='2013-02-11'>
      <description>The "S/MIME receipt requests (Open message if receipt can't be sent | Don't open message if receipt can't be sent | Always prompt before sending receipt | Never send S/MIME )" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\S/MIME receipt requests (Open message if receipt can't be sent | Don't open message if receipt can't be sent | Always prompt before sending receipt | Never send S/MIME ) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1613</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.209. S/MIME receipt requests</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\S/MIME receipt requests (Open message if receipt can't be sent | Don't open message if receipt can't be sent | Always prompt before sending receipt | Never send S/MIME )</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1402-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Fortezza certificate policies" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Fortezza certificate policies </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1402</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.156. Fortezza certificate policies</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Fortezza certificate policies</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1658-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Require SuiteB algorithms for S/MIME operations" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Require SuiteB algorithms for S/MIME operations </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1658</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.199. Require SuiteB algorithms for S/MIME operations</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Require SuiteB algorithms for S/MIME operations</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1662-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Missing CRLs" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Signature Status dialog box\Missing CRLs </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1662</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.174. Missing CRLs</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Signature Status dialog box\Missing CRLs</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1080-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Missing CRLs - Indicate a missing CRL as a(n): (warning | error)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Signature Status dialog box\Missing CRLs - Indicate a missing CRL as a(n): (warning | error) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1080</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.174. Missing CRLs</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Signature Status dialog box\Missing CRLs - Indicate a missing CRL as a(n): (warning | error)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1076-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Missing root certificates" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Signature Status dialog box\Missing root certificates </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1076</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.175. Missing root certificates</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Signature Status dialog box\Missing root certificates</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1636-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Missing root certificates - Indicate a missing root certificate as a(n): (neither error nor warning | warning | error)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Signature Status dialog box\Missing root certificates - Indicate a missing root certificate as a(n): (neither error nor warning | warning | error) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1636</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.175. Missing root certificates</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Signature Status dialog box\Missing root certificates - Indicate a missing root certificate as a(n): (neither error nor warning | warning | error)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-943-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Promote Level 2 errors as errors, not warnings" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Signature Status dialog box\Promote Level 2 errors as errors, not warnings </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-943</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.189. Promote Level 2 errors as errors, not warnings</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Signature Status dialog box\Promote Level 2 errors as errors, not warnings</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1591-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Attachment Secure Temporary Folder" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Signature Status dialog box\Attachment Secure Temporary Folder </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1591</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.18. Attachment Secure Temporary Folder</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Cryptography\Signature Status dialog box\Attachment Secure Temporary Folder</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1133-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Display pictures and external content in HTML e-mail" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Automatic Picture Download Settings\Display pictures and external content in HTML e-mail </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1133</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.127. Display pictures and external content in HTML e-mail</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Automatic Picture Download Settings\Display pictures and external content in HTML e-mail</reference>
      </references>
    </cce>
    <cce cce_id='CCE-725-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Automatically download content for e-mail from people in Safe Senders and Safe Recipients Lists" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Automatic Picture Download Settings\Automatically download content for e-mail from people in Safe Senders and Safe Recipients Lists </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-725</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.22. Automatically download content for e-mail from people in Safe Senders and Safe Recipients Lists</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Automatic Picture Download Settings\Automatically download content for e-mail from people in Safe Senders and Safe Recipients Lists</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1347-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Do not permit download of content from safe zones" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Automatic Picture Download Settings\Do not permit download of content from safe zones </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1347</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.138. Do not permit download of content from safe zones</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Automatic Picture Download Settings\Do not permit download of content from safe zones</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1475-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Block Trusted Zones" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Automatic Picture Download Settings\Block Trusted Zones </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1475</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.63. Block Trusted Zones</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Automatic Picture Download Settings\Block Trusted Zones</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1497-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Include Internet in Safe Zones for Automatic Picture Download" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Automatic Picture Download Settings\Include Internet in Safe Zones for Automatic Picture Download </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1497</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.161. Include Internet in Safe Zones for Automatic Picture Download</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Automatic Picture Download Settings\Include Internet in Safe Zones for Automatic Picture Download</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1501-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Include Intranet in Safe Zones for Automatic Picture Download" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Automatic Picture Download Settings\Include Intranet in Safe Zones for Automatic Picture Download </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1501</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.162. Include Intranet in Safe Zones for Automatic Picture Download</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Automatic Picture Download Settings\Include Intranet in Safe Zones for Automatic Picture Download</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1030-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Security setting for macros (Always warn | Never warn, disable all | Warn for signed, disable unsigned | No security check)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Trust Center\Security setting for macros (Always warn | Never warn, disable all | Warn for signed, disable unsigned | No security check) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1030</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.213. Security setting for macros</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Trust Center\Security setting for macros (Always warn | Never warn, disable all | Warn for signed, disable unsigned | No security check)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1052-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Enable links in e-mail messages" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Trust Center\Enable links in e-mail messages </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1052</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.149. Enable links in e-mail messages</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Trust Center\Enable links in e-mail messages</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1462-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Apply macro security settings to macros, add-ins, and SmartTags" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Trust Center\Apply macro security settings to macros, add-ins, and SmartTags </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1462</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.16. Apply macro security settings to macros, add-ins, and SmartTags</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Trust Center\Apply macro security settings to macros, add-ins, and SmartTags</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1281-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Automatically configure profile based on Active Directory Primary SMTP address" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Account Settings\Exchange\Automatically configure profile based on Active Directory Primary SMTP address </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\AutoDiscover</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1281</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.20. Automatically configure profile based on Active Directory Primary SMTP address</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Account Settings\Exchange\Automatically configure profile based on Active Directory Primary SMTP address</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1303-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Do not allow users to change permissions on folders" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Account Settings\Exchange\Do not allow users to change permissions on folders </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Folders</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1303</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.133. Do not allow users to change permissions on folders</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Account Settings\Exchange\Do not allow users to change permissions on folders</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1082-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Enable RPC encryption" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Account Settings\Exchange\Enable RPC encryption </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\RPC</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1082</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.150. Enable RPC encryption</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Account Settings\Exchange\Enable RPC encryption</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1712-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Authentication with Exchange Server (Kerberos/NTLM Password Authentication | Kerberos Password Authentication | NTLM Password Authentication)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Account Settings\Exchange\Authentication with Exchange Server (Kerberos/NTLM Password Authentication | Kerberos Password Authentication | NTLM Password Authentication) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1712</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.19. Authentication with Exchange Server</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Account Settings\Exchange\Authentication with Exchange Server (Kerberos/NTLM Password Authentication | Kerberos Password Authentication | NTLM Password Authentication)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1131-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Synchronize Outlook RSS Feeds with Common Feed List" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Account Settings\RSS Feeds\Synchronize Outlook RSS Feeds with Common Feed List </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\RSS</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1131</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.224. Synchronize Outlook RSS Feeds with Common Feed List</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Account Settings\RSS Feeds\Synchronize Outlook RSS Feeds with Common Feed List</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1620-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Turn off RSS feature" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Account Settings\RSS Feeds\Turn off RSS feature </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\RSS</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1620</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.228. Turn off RSS feature</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Account Settings\RSS Feeds\Turn off RSS feature</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1541-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Automatically download enclosures" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Account Settings\RSS Feeds\Automatically download enclosures </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\RSS</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1541</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Account Settings\RSS Feeds\Automatically download enclosures</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1311-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Download full text of articles as HTML attachments" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Account Settings\RSS Feeds\Download full text of articles as HTML attachments </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\RSS</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1311</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.145. Download full text of articles as HTML attachments</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Account Settings\RSS Feeds\Download full text of articles as HTML attachments</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1682-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Automatically download attachments" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Account Settings\Internet Calendars\Automatically download attachments </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\WebCal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1682</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.21. Automatically download attachments</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Account Settings\Internet Calendars\Automatically download attachments</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1461-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Do not include Internet Calendar integration in Outlook" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Account Settings\Internet Calendars\Do not include Internet Calendar integration in Outlook </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\WebCal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1461</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.137. Do not include Internet Calendar integration in Outlook</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Tools | Account Settings\Internet Calendars\Do not include Internet Calendar integration in Outlook</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1041-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable user entries to server list (Publish default, allow others | Publish default, disallow others)" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Meeting Workspace\Disable user entries to server list (Publish default, allow others | Publish default, disallow others) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Meetings\Profile</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1041</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.123. Disable user entries to server list</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Meeting Workspace\Disable user entries to server list (Publish default, allow others | Publish default, disallow others)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1565-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Do not expand distribution lists" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Miscellaneous\Do not expand distribution lists </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Outlook\Options\Mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1565</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.136. Do not expand distribution lists</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Miscellaneous\Do not expand distribution lists</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1719-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Save files in this format (PowerPoint Presentation (*.pptx) | PowerPoint Macro-Enabled Presentation (*.pptm) | PowerPoint 97-2003 Presentation (*.ppt))" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Save\Save files in this format (PowerPoint Presentation (*.pptx) | PowerPoint Macro-Enabled Presentation (*.pptm) | PowerPoint 97-2003 Presentation (*.ppt)) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1719</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.212. Save files in this format</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Save\Save files in this format (PowerPoint Presentation (*.pptx) | PowerPoint Macro-Enabled Presentation (*.pptm) | PowerPoint 97-2003 Presentation (*.ppt))</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1477-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Number of documents in the Recent Documents list (0 - 50)" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Advanced\Number of documents in the Recent Documents list (0 - 50) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\File MRU</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1477</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Advanced\Number of documents in the Recent Documents list (0 - 50)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1142-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Determine whether to force encrypted macros to be scanned in Microsoft PowerPoint Open XML presentations" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Security\Determine whether to force encrypted macros to be scanned in Microsoft PowerPoint Open XML presentations </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1142</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.82. Determine whether to force encrypted macros to be scanned in Microsoft PowerPoint Open XML presentations</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Security\Determine whether to force encrypted macros to be scanned in Microsoft PowerPoint Open XML presentations</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1649-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Run Programs (disable (don't run any programs) | enable (prompt user before running) | enable all (run without prompting))" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Security\Run Programs (disable (don't run any programs) | enable (prompt user before running) | enable all (run without prompting)) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1649</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.206. Run Programs</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Security\Run Programs (disable (don't run any programs) | enable (prompt user before running) | enable all (run without prompting))</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1279-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Make hidden markup visible" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Security\Make hidden markup visible </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1279</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.170. Make hidden markup visible</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Security\Make hidden markup visible</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1451-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Unblock automatic download of linked images" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Security\Unblock automatic download of linked images </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1451</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.229. Unblock automatic download of linked images</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Security\Unblock automatic download of linked images</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1204-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable all application add-ins" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Security\Trust Center\Disable all application add-ins </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1204</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.87. Disable all application add-ins</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Security\Trust Center\Disable all application add-ins</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1107-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Require that application add-ins are signed by Trusted Publisher" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Security\Trust Center\Require that application add-ins are signed by Trusted Publisher </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1107</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.200. Require that application add-ins are signed by Trusted Publisher</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Security\Trust Center\Require that application add-ins are signed by Trusted Publisher</reference>
      </references>
    </cce>
    <cce cce_id='CCE-743-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable Trust Bar Notification for unsigned application add-ins" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Security\Trust Center\Disable Trust Bar Notification for unsigned application add-ins </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-743</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.120. Disable Trust Bar Notification for unsigned application add-ins</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Security\Trust Center\Disable Trust Bar Notification for unsigned application add-ins</reference>
      </references>
    </cce>
    <cce cce_id='CCE-747-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Allow Trusted Locations not on the computer" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Security\Trust Center\Trusted LocationsAllow Trusted Locations not on the computer </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\Trusted Locations</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-747</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.11. Allow Trusted Locations not on the computer</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Security\Trust Center\Trusted LocationsAllow Trusted Locations not on the computer</reference>
      </references>
    </cce>
    <cce cce_id='CCE-782-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable all trusted locations" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Security\Trust Center\Trusted LocationsDisable all trusted locations </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\Trusted Locations</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-782</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.89. Disable all trusted locations</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\PowerPoint Options\Security\Trust Center\Trusted LocationsDisable all trusted locations</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1327-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1327</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1723-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Office Button | PowerPoint Options | Customize | All Commands | Web Page Preview" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Office Button | PowerPoint Options | Customize | All Commands | Web Page Preview </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1723</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Office Button | PowerPoint Options | Customize | All Commands | Web Page Preview</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1366-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Office Button | Send | Email" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Office Button | Send | Email </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1366</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Office Button | Send | Email</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1679-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Insert | Links | Hyperlink" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Insert | Links | Hyperlink </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1679</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Insert | Links | Hyperlink</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1173-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Review | Proofing | Language" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Review | Proofing | Language </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1173</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Review | Proofing | Language</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1714-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - View | Macros | Macros" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - View | Macros | Macros </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1714</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - View | Macros | Macros</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1485-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Developer | Code | Macros" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Macros </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1485</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Macros</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1687-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Developer | Code | Macro Security" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Macro Security </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1687</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Macro Security</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1709-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Developer | Code | Visual Basic" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Visual Basic </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1709</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Visual Basic</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1463-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Office Button | PowerPoint Options | Customize | All Commands | Document Location" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Office Button | PowerPoint Options | Customize | All Commands | Document Location </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1463</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Office Button | PowerPoint Options | Customize | All Commands | Document Location</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1467-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Disable shortcut keys" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Disable shortcut keys </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\DisabledShortcutKeysCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1467</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands, Table 1.114. Disable shortcut keys</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Disable shortcut keys</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1740-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Ctrl+K (Insert | Links |  Hyperlink)" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Ctrl+K (Insert | Links |  Hyperlink) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\DisabledShortcutKeysCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1740</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands, Table 1.114. Disable shortcut keys</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Ctrl+K (Insert | Links |  Hyperlink)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1780-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Alt+F8 (Developer | Code | Macros)" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Alt+F8 (Developer | Code | Macros) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\DisabledShortcutKeysCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1780</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands, Table 1.114. Disable shortcut keys</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Alt+F8 (Developer | Code | Macros)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1661-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Alt+F11 (Developer | Code | Visual Basic)" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Alt+F11 (Developer | Code | Visual Basic) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\DisabledShortcutKeysCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1661</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands, Table 1.114. Disable shortcut keys</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Disable items in user interface\Predefined\Disable commands - Alt+F11 (Developer | Code | Visual Basic)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1688-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of pre-release versions of file formats new to PowerPoint 2007" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Open\Block opening of pre-release versions of file formats new to PowerPoint 2007 </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1688</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.41. Block opening of pre-release versions of file formats new to PowerPoint 2007</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Open\Block opening of pre-release versions of file formats new to PowerPoint 2007</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1701-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of Open Xml files types" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Open\Block opening of Open Xml files types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1701</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.38. Block opening of Open XML file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Open\Block opening of Open Xml files types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1348-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of Binary file types" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Open\Block opening of Binary file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1348</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.30. Block opening of Binary file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Open\Block opening of Binary file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1644-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of Html file types" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Open\Block opening of Html file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1644</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.36. Block opening of HTML file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Open\Block opening of Html file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1194-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of Outlines" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Open\Block opening of Outlines </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1194</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.39. Block opening of Outlines</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Open\Block opening of Outlines</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1216-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of Converters" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Open\Block opening of Converters </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1216</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.31. Block opening of Converters</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Open\Block opening of Converters</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1506-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Block saving of Open Xml file types" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Save\Block saving of Open Xml file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\FileSaveBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1506</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.57. Block saving of Open Xml file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Save\Block saving of Open Xml file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1136-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Block saving of Binary file types" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Save\Block saving of Binary file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\FileSaveBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1136</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.51. Block saving of Binary file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Save\Block saving of Binary file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1766-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Block saving of Html file types" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Save\Block saving of Html file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\FileSaveBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1766</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.56. Block saving of HTML file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Save\Block saving of Html file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1180-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Block saving of Outlines" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Save\Block saving of Outlines </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\FileSaveBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1180</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.58. Block saving of Outlines</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Save\Block saving of Outlines</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1722-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Block saving of GraphicFilters" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Save\Block saving of GraphicFilters </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\Security\FileSaveBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1722</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.54. Block saving of GraphicFilters</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Save\Block saving of GraphicFilters</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1731-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable Slide Update" setting should be configured correctly for PowerPoint 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Miscellaneous\Disable Slide Update </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\PowerPoint\slide libraries</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1731</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.115. Disable Slide Update</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office PowerPoint 2007\Block file formats\Miscellaneous\Disable Slide Update</reference>
      </references>
    </cce>
    <cce cce_id='CCE-885-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Hidden text" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Display\Hidden text </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-885</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.157. Hidden text</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Display\Hidden text</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1656-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Save files in this format (Word document (*.docx) | Single Files Web Page (*.mht) | Web Page (*.htm; *.html) | Web Page, Filtered (*.htm, *.html) | Rich Text Format (*.rtf) | Plain Text  (*.txt) | Word 6.0/95 (*.doc) | Word 6.0/95 - Chinese (Simplified) (*.doc) | Word 6.0/95 - Chinese (Traditional) (*.doc) | Word 6.0/95 - Japanese (*.doc) | Word 6.0/95 - Korean (*.doc) | Word 97-2002 &amp; 6.0/95 - RTF | Word 5.1 for Macintosh (*.mcw) | Word 5.0 for Macintosh (*.mcw) | Word 2.x for Windows (*.doc) | Works 4.0 for Windows (*.wps) | WordPerfect 5.x for Windows (*.doc) | WordPerfect 5.1 for DOS (*.doc) | Word 2007 Macro Enabled Document (*.docm) | Word 2007 Macro Free Template (*.dotx) | Word 2007 Macro Enabled Template (*.dotm) | Word 97 - 2003 Document (*.doc) | Word 97 - 2003 Template (*.dot) | Flat XML Document (*.xml))" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Save\Save files in this format (Word document (*.docx) | Single Files Web Page (*.mht) | Web Page (*.htm; *.html) | Web Page, Filtered (*.htm, *.html) | Rich Text Format (*.rtf) | Plain Text  (*.txt) | Word 6.0/95 (*.doc) | Word 6.0/95 - Chinese (Simplified) (*.doc) | Word 6.0/95 - Chinese (Traditional) (*.doc) | Word 6.0/95 - Japanese (*.doc) | Word 6.0/95 - Korean (*.doc) | Word 97-2002 &amp; 6.0/95 - RTF | Word 5.1 for Macintosh (*.mcw) | Word 5.0 for Macintosh (*.mcw) | Word 2.x for Windows (*.doc) | Works 4.0 for Windows (*.wps) | WordPerfect 5.x for Windows (*.doc) | WordPerfect 5.1 for DOS (*.doc) | Word 2007 Macro Enabled Document (*.docm) | Word 2007 Macro Free Template (*.dotx) | Word 2007 Macro Enabled Template (*.dotm) | Word 97 - 2003 Document (*.doc) | Word 97 - 2003 Template (*.dot) | Flat XML Document (*.xml)) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1656</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.212. Save files in this format</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Save\Save files in this format (Word document (*.docx) | Single Files Web Page (*.mht) | Web Page (*.htm; *.html) | Web Page, Filtered (*.htm, *.html) | Rich Text Format (*.rtf) | Plain Text  (*.txt) | Word 6.0/95 (*.doc) | Word 6.0/95 - Chinese (Simplified) (*.doc) | Word 6.0/95 - Chinese (Traditional) (*.doc) | Word 6.0/95 - Japanese (*.doc) | Word 6.0/95 - Korean (*.doc) | Word 97-2002 &amp; 6.0/95 - RTF | Word 5.1 for Macintosh (*.mcw) | Word 5.0 for Macintosh (*.mcw) | Word 2.x for Windows (*.doc) | Works 4.0 for Windows (*.wps) | WordPerfect 5.x for Windows (*.doc) | WordPerfect 5.1 for DOS (*.doc) | Word 2007 Macro Enabled Document (*.docm) | Word 2007 Macro Free Template (*.dotx) | Word 2007 Macro Enabled Template (*.dotm) | Word 97 - 2003 Document (*.doc) | Word 97 - 2003 Template (*.dot) | Flat XML Document (*.xml))</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1537-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Number of documents in the Recent Documents list (0-50)" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Advanced\Number of documents in the Recent Documents list (0-50) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\File MRU</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1537</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Advanced\Number of documents in the Recent Documents list (0-50)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1249-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Update automatic links at Open" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Advanced\Update automatic links at Open </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1249</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.231. Update automatic links at Open</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Advanced\Update automatic links at Open</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1509-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Save smart tags in e-mail" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Advanced\E-mail Options\Save smart tags in e-mail </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1509</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Advanced\E-mail Options\Save smart tags in e-mail</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1280-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Determine whether to force encrypted macros to be scanned in Microsoft Word Open XML documents" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Security\Trust Center\Determine whether to force encrypted macros to be scanned in Microsoft Word Open XML documents </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1280</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.83. Determine whether to force encrypted macros to be scanned in Microsoft Word Open XML documents</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Security\Trust Center\Determine whether to force encrypted macros to be scanned in Microsoft Word Open XML documents</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1681-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable all application add-ins" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Security\Trust Center\Disable all application add-ins </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1681</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.87. Disable all application add-ins</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Security\Trust Center\Disable all application add-ins</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1562-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Require that application add-ins are signed by Trusted Publisher" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Security\Trust Center\Require that application add-ins are signed by Trusted Publisher </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1562</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.200. Require that application add-ins are signed by Trusted Publisher</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Security\Trust Center\Require that application add-ins are signed by Trusted Publisher</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1333-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable Trust Bar Notification for unsigned application add-ins" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Security\Trust Center\Disable Trust Bar Notification for unsigned application add-ins </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1333</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.120. Disable Trust Bar Notification for unsigned application add-ins</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Security\Trust Center\Disable Trust Bar Notification for unsigned application add-ins</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1355-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Allow Trusted Locations not on the computer" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Security\Trust Center\Trusted LocationsAllow Trusted Locations not on the computer </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security\Trusted Locations</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1355</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.11. Allow Trusted Locations not on the computer</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Security\Trust Center\Trusted LocationsAllow Trusted Locations not on the computer</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1637-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable all trusted locations" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Security\Trust Center\Trusted LocationsDisable all trusted locations </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security\Trusted Locations</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1637</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.89. Disable all trusted locations</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Word Options\Security\Trust Center\Trusted LocationsDisable all trusted locations</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1659-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1659</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1329-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Office Button | Word Options | Customize | All Commands | Save As Web Page" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - Office Button | Word Options | Customize | All Commands | Save As Web Page </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1329</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - Office Button | Word Options | Customize | All Commands | Save As Web Page</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1632-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Office Button | Word Options | Customize | All Commands | Web Page Preview" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - Office Button | Word Options | Customize | All Commands | Web Page Preview </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1632</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - Office Button | Word Options | Customize | All Commands | Web Page Preview</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1425-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Office Button | Send | Email" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - Office Button | Send | Email </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1425</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - Office Button | Send | Email</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1196-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Insert | Links | Hyperlink" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - Insert | Links | Hyperlink </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1196</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - Insert | Links | Hyperlink</reference>
      </references>
    </cce>
    <cce cce_id='CCE-936-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Review | Protect | Protect Document" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - Review | Protect | Protect Document </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-936</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - Review | Protect | Protect Document</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1354-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - View | Macros | Macros" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - View | Macros | Macros </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1354</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - View | Macros | Macros</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1125-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Developer | Code | Macros" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Macros </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1125</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Macros</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1742-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Developer | Code | Record Macro" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Record Macro </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1742</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Record Macro</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1782-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Developer | Code | Macro Security" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Macro Security </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1782</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Macro Security</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1306-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Developer | Code | Visual Basic" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Visual Basic </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1306</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - Developer | Code | Visual Basic</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1548-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable commands - Developer | Templates | Document Template" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - Developer | Templates | Document Template </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\DisabledCmdBarItemsCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1548</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.94. Disable commands</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable commands - Developer | Templates | Document Template</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1716-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable shortcut keys" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable shortcut keys </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\DisabledShortcutKeysCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1716</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.114. Disable shortcut keys</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable shortcut keys</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1597-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable shortcut keys - Ctrl+F (Home | Editing | Find)" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable shortcut keys - Ctrl+F (Home | Editing | Find) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\DisabledShortcutKeysCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1597</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.114. Disable shortcut keys</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable shortcut keys - Ctrl+F (Home | Editing | Find)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1689-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable shortcut keys - Ctrl+K (Insert | Links | Hyperlink)" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable shortcut keys - Ctrl+K (Insert | Links | Hyperlink) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\DisabledShortcutKeysCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1689</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.114. Disable shortcut keys</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable shortcut keys - Ctrl+K (Insert | Links | Hyperlink)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1570-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable shortcut keys - Alt+F8 (Developer | Code | Macros)" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable shortcut keys - Alt+F8 (Developer | Code | Macros) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\DisabledShortcutKeysCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1570</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.114. Disable shortcut keys</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable shortcut keys - Alt+F8 (Developer | Code | Macros)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1720-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable shortcut keys - Alt+F11 (Developer | Code | Visual Basic)" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable shortcut keys - Alt+F11 (Developer | Code | Visual Basic) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\DisabledShortcutKeysCheckBoxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1720</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.114. Disable shortcut keys</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Disable items in user interface\Predefined\Disable shortcut keys - Alt+F11 (Developer | Code | Visual Basic)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1746-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of pre-release versions of file formats new to Word 2007" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Open\Block opening of pre-release versions of file formats new to Word 2007 </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1746</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.43. Block opening of pre-release versions of file formats new to Word 2007</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Open\Block opening of pre-release versions of file formats new to Word 2007</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1504-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of Open XML file types" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Open\Block opening of Open XML file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1504</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.38. Block opening of Open XML file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Open\Block opening of Open XML file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1654-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of Binary file types" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Open\Block opening of Binary file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1654</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.30. Block opening of Binary file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Open\Block opening of Binary file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1160-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of HTML file types" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Open\Block opening of HTML file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1160</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.36. Block opening of HTML file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Open\Block opening of HTML file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-958-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of Word 2003 XML file types" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Open\Block opening of Word 2003 XML file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-958</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.47. Block opening of Word 2003 XML file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Open\Block opening of Word 2003 XML file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1579-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of RTF file types" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Open\Block opening of RTF file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1579</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.45. Block opening of RTF file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Open\Block opening of RTF file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-984-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Block open Converters" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Open\Block open Converters </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-984</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.28. Block open Converters</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Open\Block open Converters</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1072-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of Text file types" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Open\Block opening of Text file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1072</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.46. Block opening of Text file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Open\Block opening of Text file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1503-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of Internal file types" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Open\Block opening of Internal file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1503</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.37. Block opening of Internal file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Open\Block opening of Internal file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1371-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Block opening of files before version" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Open\Block opening of files before version </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security\FileOpenBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1371</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.33. Block opening of files before version</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Open\Block opening of files before version</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1019-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Block saving of Open XML file types" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Save\Block saving of Open XML file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security\FileSaveBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1019</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.57. Block saving of Open Xml file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Save\Block saving of Open XML file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1684-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Block saving of Binary file types" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Save\Block saving of Binary file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security\FileSaveBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1684</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.51. Block saving of Binary file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Save\Block saving of Binary file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1675-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Block saving of HTML file types" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Save\Block saving of HTML file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security\FileSaveBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1675</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.56. Block saving of HTML file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Save\Block saving of HTML file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1200-5' platform='office2k7' modified='2013-02-11'>
      <description>The "Block saving of Word 2003 XML file types" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Save\Block saving of Word 2003 XML file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security\FileSaveBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1200</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.61. Block saving of Word 2003 XML file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Save\Block saving of Word 2003 XML file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1741-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Block saving of RTF file types" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Save\Block saving of RTF file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security\FileSaveBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1741</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.59. Block saving of RTF file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Save\Block saving of RTF file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1231-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Block saving of Converters" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Save\Block saving of Converters </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security\FileSaveBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1231</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.53. Block saving of Converters</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Save\Block saving of Converters</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1755-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Block saving of Text file types" setting should be configured correctly for Word 2007.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Save\Block saving of Text file types </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Word\Security\FileSaveBlock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1755</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 1.60. Block saving of Text file types</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Microsoft Office Word 2007\Block file formats\Save\Block saving of Text file types</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1169-2' platform='office2k7' modified='2013-02-11'>
      <description>The InfoPath APTCA Assembly Whitelist setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office InfoPath 2007 (Machine)\Security\InfoPath APTCA Assembly Whitelist </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security\APTCA</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1169</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.6. InfoPath APTCA Assembly allowable list</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office InfoPath 2007 (Machine)\Security\InfoPath APTCA Assembly Whitelist</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1735-0' platform='office2k7' modified='2013-02-11'>
      <description>The Windows Internet Explorer Feature Control Opt-In (None | InfoPath.exe, Document Information Panel and Workflow forms | InfoPath.exe, Document Information Panel, Workflow forms and 3rd Party Hosting) setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office InfoPath 2007 (Machine)\Security\Windows Internet Explorer Feature Control Opt-In (None | InfoPath.exe, Document Information Panel and Workflow forms | InfoPath.exe, Document Information Panel, Workflow forms and 3rd Party Hosting) </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1735</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office InfoPath 2007 (Machine)\Security\Windows Internet Explorer Feature Control Opt-In (None | InfoPath.exe, Document Information Panel and Workflow forms | InfoPath.exe, Document Information Panel, Workflow forms and 3rd Party Hosting)</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1739-2' platform='office2k7' modified='2013-02-11'>
      <description>The InfoPath APTCA Assembly Whitelist Enforcement setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office InfoPath 2007 (Machine)\Security\InfoPath APTCA Assembly Whitelist Enforcement </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\InfoPath\Security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1739</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.7. InfoPath APTCA Assembly Allowable List Enforcement</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office InfoPath 2007 (Machine)\Security\InfoPath APTCA Assembly Whitelist Enforcement</reference>
      </references>
    </cce>
    <cce cce_id='CCE-933-2' platform='office2k7' modified='2013-02-11'>
      <description>The Disable Package Repair setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\Disable Package Repair </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Office\12.0\Common\OpenXMLFormat</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-933</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.3. Disable Package Repair</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\Disable Package Repair</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1563-6' platform='office2k7' modified='2013-02-11'>
      <description>The Disable user name and password setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Disable user name and password </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1563</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.4. Disable user name and password</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Disable user name and password</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1215-3' platform='office2k7' modified='2013-02-11'>
      <description>The Disable user name and password - excel.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Disable user name and password - excel.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1215</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.4. Disable user name and password</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Disable user name and password - excel.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO104 - Excel Rule ID: SV-18567r3_rule Vuln ID: V-17173: Disable user name and password syntax from being used in URLs.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1484-5' platform='office2k7' modified='2013-02-11'>
      <description>The Disable user name and password - powerpnt.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Disable user name and password - powerpnt.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1484</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.4. Disable user name and password</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Disable user name and password - powerpnt.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO104 - PowerPoint Rule ID: SV-18179r3_rule Vuln ID: V-17173: Disable user name and password syntax from being used in URLs.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1629-5' platform='office2k7' modified='2013-02-11'>
      <description>The Disable user name and password - pptview.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Disable user name and password - pptview.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1629</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.4. Disable user name and password</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Disable user name and password - pptview.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO104 - PowerPoint Rule ID: SV-18179r3_rule Vuln ID: V-17173: Disable user name and password syntax from being used in URLs.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1762-4' platform='office2k7' modified='2013-02-11'>
      <description>The Disable user name and password - winword.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Disable user name and password - winword.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1762</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.4. Disable user name and password</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Disable user name and password - winword.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO104 - Word Rule ID: SV-18180r3_rule Vuln ID: V-17173: Disable user name and password for Word.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1660-0' platform='office2k7' modified='2013-02-11'>
      <description>The Disable user name and password - outlook.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Disable user name and password - outlook.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1660</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.4. Disable user name and password</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Disable user name and password - outlook.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO104 - Outlook Rule ID: SV-18181r3_rule Vuln ID: V-17173 Disable user name and password syntax from being used in URLs</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1057-9' platform='office2k7' modified='2013-02-11'>
      <description>The Disable user name and password - spDesign.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Disable user name and password - spDesign.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1057</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.4. Disable user name and password</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Disable user name and password - spDesign.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO104 - InfoPath Rule ID: SV-18182r3_rule Vuln ID: V-17173 Disable user name and password syntax from being used in URLs</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1285-6' platform='office2k7' modified='2013-02-11'>
      <description>The Disable user name and password - msaccess.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Disable user name and password - msaccess.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1285</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.4. Disable user name and password</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Disable user name and password - msaccess.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO104 - Access Rule ID: SV-19429r3_rule Vuln ID: V-17173: Disable user name and password syntax from being used in URLs</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1669-1' platform='office2k7' modified='2013-02-11'>
      <description>The Bind to object setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Bind to object </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1669</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.1. Bind to object</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Bind to object</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1691-5' platform='office2k7' modified='2013-02-11'>
      <description>The Bind to object - excel.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Bind to object - excel.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1691</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.1. Bind to object</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Bind to object - excel.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO111 - Excel Rule ID: SV-18185r3_rule Vuln ID: V-17174: Bind to Object - Excel</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1338-3' platform='office2k7' modified='2013-02-11'>
      <description>The Bind to object - powerpnt.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Bind to object - powerpnt.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1338</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.1. Bind to object</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Bind to object - powerpnt.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO111 - PowerPoint Rule ID: SV-18186r3_rule Vuln ID: V-17174: Enable IE Bind to Object functionality for instances of IE launched from PowerPoint.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1717-8' platform='office2k7' modified='2013-02-11'>
      <description>The Bind to object - pptview.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Bind to object - pptview.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1717</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.1. Bind to object</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Bind to object - pptview.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO111 - PowerPoint Rule ID: SV-18186r3_rule Vuln ID: V-17174: Enable IE Bind to Object functionality for instances of IE launched from PowerPoint.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1488-6' platform='office2k7' modified='2013-02-11'>
      <description>The Bind to object - winword.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Bind to object - winword.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1488</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.1. Bind to object</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Bind to object - winword.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO111 - Word Rule ID: SV-18187r3_rule Vuln ID: V-17174: Enable IE Bind to Object functionality for instances of IE launched from Word.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1638-6' platform='office2k7' modified='2013-02-11'>
      <description>The Bind to object - outlook.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Bind to object - outlook.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1638</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.1. Bind to object</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Bind to object - outlook.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO111 - Outlook Rule ID: SV-18188r3_rule Vuln ID: V-17174: Enable IE Bind to Object functionality for instances of IE launched from Outlook</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1647-7' platform='office2k7' modified='2013-02-11'>
      <description>The Bind to object - spDesign.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Bind to object - spDesign.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1647</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.1. Bind to object</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Bind to object - spDesign.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO111 - InfoPath Rule ID: SV-18189r3_rule Vuln ID: V-17174: Enable IE Bind to Object functionality for instances of IE launched from InfoPath.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1294-8' platform='office2k7' modified='2013-02-11'>
      <description>The Bind to object - msaccess.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Bind to object - msaccess.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SAFE_BINDTOOBJECT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1294</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.1. Bind to object</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Bind to object - msaccess.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO111 - Access Rule ID: SV-18190r3_rule Vuln ID: V-17174: Bind to Object - Access</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1193-2' platform='office2k7' modified='2013-02-11'>
      <description>The Saved from URL setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Saved from URL </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1193</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.9. Saved from URL</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Saved from URL</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1352-4' platform='office2k7' modified='2013-02-11'>
      <description>The Saved from URL - excel.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Saved from URL - excel.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1352</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.9. Saved from URL</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Saved from URL - excel.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO117 - Excel Rule ID: SV-18200r3_rule Vuln ID: V-17175: Evaluate Saved from URL mark when launched from Excel</reference>
      </references>
    </cce>
    <cce cce_id='CCE-928-2' platform='office2k7' modified='2013-02-11'>
      <description>The Saved from URL - powerpnt.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Saved from URL - powerpnt.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-928</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.9. Saved from URL</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Saved from URL - powerpnt.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO117 - PowerPoint Rule ID: SV-18201r3_rule Vuln ID: V-17175: Evaluate Saved from URL mark when launched from PowerPoint</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1576-8' platform='office2k7' modified='2013-02-11'>
      <description>The Saved from URL - pptview.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Saved from URL - pptview.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1576</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.9. Saved from URL</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Saved from URL - pptview.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO117 - PowerPoint Rule ID: SV-18201r3_rule Vuln ID: V-17175: Evaluate Saved from URL mark when launched from PowerPoint</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1100-7' platform='office2k7' modified='2013-02-11'>
      <description>The Saved from URL - word.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Saved from URL - winword.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1100</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.9. Saved from URL</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Saved from URL - winword.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO117 - Word Rule ID: SV-18202r3_rule Vuln ID: V-17175: Saved from URL - Word</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1232-8' platform='office2k7' modified='2013-02-11'>
      <description>The Saved from URL - outlook.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Saved from URL - outlook.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1232</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.9. Saved from URL</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Saved from URL - outlook.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO117 - Outlook Rule ID: SV-18203r3_rule Vuln ID: V-17175: Evaluate Saved from URL mark when launched from OutLook</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1774-9' platform='office2k7' modified='2013-02-11'>
      <description>The Saved from URL - spDesign.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Saved from URL - spDesign.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1774</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.9. Saved from URL</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Saved from URL - spDesign.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO117 - InfoPath Rule ID: SV-18204r3_rule Vuln ID: V-17175: Evaluate Saved from URL mark when launched from InfoPath.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-906-8' platform='office2k7' modified='2013-02-11'>
      <description>The Saved from URL - msaccess.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Saved from URL - msaccess.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_UNC_SAVEDFILECHECK</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-906</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.9. Saved from URL</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Saved from URL - msaccess.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO117 - Access Rule ID: SV-18205r3_rule Vuln ID: V-17175: Saved from URL - Access</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1034-8' platform='office2k7' modified='2013-02-11'>
      <description>The Navigate URL setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Navigate URL </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1034</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.8. Navigate URL</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Navigate URL</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1435-7' platform='office2k7' modified='2013-02-11'>
      <description>The Navigate URL - excel.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Navigate URL - excel.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1435</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.8. Navigate URL</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Navigate URL - excel.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO123 - Excel Rule ID: SV-18207r3_rule Vuln ID: V-17183: Block navigation to URL embedded in Office products to protect against attack by malformed URL.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1708-7' platform='office2k7' modified='2013-02-11'>
      <description>The Navigate URL - powerpnt.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Navigate URL - powerpnt.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1708</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.8. Navigate URL</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Navigate URL - powerpnt.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO123 - PowerPoint Rule ID: SV-18208r3_rule Vuln ID: V-17183: Block navigation to URL embedded in Office products to protect against attack by malformed URL.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-808-6' platform='office2k7' modified='2013-02-11'>
      <description>The Navigate URL - pptview.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Navigate URL - pptview.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-808</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.8. Navigate URL</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Navigate URL - pptview.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO123 - PowerPoint Rule ID: SV-18208r3_rule Vuln ID: V-17183: Block navigation to URL embedded in Office products to protect against attack by malformed URL.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1650-1' platform='office2k7' modified='2013-02-11'>
      <description>The Navigate URL - winword.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Navigate URL - winword.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1650</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.8. Navigate URL</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Navigate URL - winword.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO123 - Word Rule ID: SV-18604r3_rule Vuln ID: V-17183: Block navigation to URL embedded in Office products to protect against attack by malformed URL.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1223-7' platform='office2k7' modified='2013-02-11'>
      <description>The Navigate URL - outlook.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Navigate URL - outlook.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1223</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.8. Navigate URL</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Navigate URL - outlook.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO123 - Outlook Rule ID: SV-18602r4_rule Vuln ID: V-17183: Block navigation to URL embedded in Office products to protect against attack by malformed URL.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1764-0' platform='office2k7' modified='2013-02-11'>
      <description>The Navigate URL - spDesign.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Navigate URL - spDesign.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1764</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.8. Navigate URL</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Navigate URL - spDesign.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO123 - InfoPath Rule ID: SV-18601r3_rule Vuln ID: V-17183: Block navigation to URL embedded in Office products to protect against attack by malformed URL.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1769-9' platform='office2k7' modified='2013-02-11'>
      <description>The Navigate URL - msaccess.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Navigate URL - msaccess.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_VALIDATE_NAVIGATE_URL</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1769</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.8. Navigate URL</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Navigate URL - msaccess.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO123 - Access Rule ID: SV-18603r4_rule Vuln ID: V-17183: Block navigation to URL embedded in Office products to protect against attack by malformed URL.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1152-8' platform='office2k7' modified='2013-02-11'>
      <description>The Block popups setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Block popups </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1152</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.2. Block popups</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Block popups</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1566-9' platform='office2k7' modified='2013-02-11'>
      <description>The Block popups - excel.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Block popups - excel.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1566</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.2. Block popups</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Block popups - excel.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO129 - Excel Rule ID: SV-18210r3_rule Vuln ID: V-17184: Block pop-ups for links that invoke instances of IE from within Excel</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1077-7' platform='office2k7' modified='2013-02-11'>
      <description>The Block popups - powerpnt.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Block popups - powerpnt.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1077</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.2. Block popups</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Block popups - powerpnt.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO129 - PowerPoint Rule ID: SV-18211r3_rule Vuln ID: V-17184: Block pop-ups for links that invoke instances of IE from within PowerPoint.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1606-3' platform='office2k7' modified='2013-02-11'>
      <description>The Block popups - pptview.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Block popups - pptview.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1606</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.2. Block popups</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Block popups - pptview.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO129 - PowerPoint Rule ID: SV-18211r3_rule Vuln ID: V-17184: Block pop-ups for links that invoke instances of IE from within PowerPoint.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1738-4' platform='office2k7' modified='2013-02-11'>
      <description>The Block popups - winword.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Block popups - winword.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1738</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.2. Block popups</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Block popups - winword.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO129 - Word Rule ID: SV-18212r4_rule Vuln ID: V-17184: Block pop-ups for links that invoke instances of IE from within Word.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1262-5' platform='office2k7' modified='2013-02-11'>
      <description>The Block popups - outlook.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Block popups - outlook.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1262</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.2. Block popups</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Block popups - outlook.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO129 - Outlook Rule ID: SV-18213r3_rule Vuln ID: V-17184: Block pop-ups for links that invoke instances of IE from within Outlook.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1663-4' platform='office2k7' modified='2013-02-11'>
      <description>The Block popups - spDesign.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Block popups - spDesign.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1663</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.2. Block popups</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Block popups - spDesign.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO129 - InfoPath Rule ID: SV-18214r3_rule Vuln ID: V-17184: Block pop-ups for links that invoke instances of IE from within InfoPath.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1544-6' platform='office2k7' modified='2013-02-11'>
      <description>The Block popups - msaccess.exe setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Block popups - msaccess.exe </technical_mechanism>
        <technical_mechanism>(2)  Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1544</reference>
        <reference resource_id='Microsoft Office 2007 Threats and Countermeasures guide Beta release'>Table 2.2. Block popups</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Microsoft Office 2007 system (Machine)\Security Settings\IE Security\Block popups - msaccess.exe</reference>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO129 - Access Rule ID: SV-18215r3_rule Vuln ID: V-17184: No pop-ups - Access</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1443-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Prevent users from customizing attachment security settings" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) 1 = Enabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2007\Security\Prevent users from customizing attachment security settings </technical_mechanism>
        <technical_mechanism>(2)  HKCU\Software\Policies\Microsoft\Office\12.0\Outlook - DisallowAttachmentCustomization</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1443</reference>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Classic Administrative Templates\Microsoft Office Outlook 2007\Security\Prevent users from customizing attachment security settings</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1161-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Access:  Macro Security Level" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) 1 = Enabled - Low | 2 = Enabled - Medium | 3 = Enabled - High</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2003\Security Settings\Access:  Macro Security Leve </technical_mechanism>
        <technical_mechanism>(2)  HKLM\Software\Policies\Microsoft\Office\11.0\Access\Security - Level </technical_mechanism>
        <technical_mechanism>(3)  User Configuration\Administrative Templates\Microsoft Office Access 2003\Tools\Macros\Security\Security level </technical_mechanism>
        <technical_mechanism>(4)  HKCU\Software\Policies\Microsoft\Office\11.0\Access\Security - Level</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1161</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1421-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Access: Trust all installed add – ins and templates" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2003\Security Settings\Access: Trust all installed add – ins and templates </technical_mechanism>
        <technical_mechanism>(2)  HKLM\Software\Policies\Microsoft\Office\11.0\Access\Security - DontTrustInstalledFiles </technical_mechanism>
        <technical_mechanism>(3)  User Configuration\Administrative Templates\Microsoft Office Access 2003\Tools\Macros\Security\Trust all installed add-ins and templates </technical_mechanism>
        <technical_mechanism>(4)  HKCU\Software\Policies\Microsoft\Office\11.0\Access\Security - DontTrustInstalledFiles</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1421</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1571-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Excel: Macro Security Level" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1)  1 = Enabled - Low | 2 = Enabled - Medium | 3 = Enabled - High</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2003\Security Settings\Excel: Macro Security Level </technical_mechanism>
        <technical_mechanism>(2)  HKLM\Software\Policies\Microsoft\Office\11.0\Excel\Security - Level</technical_mechanism>
        <technical_mechanism>(3)  User Configuration\Administrative Templates\Microsoft Office Excel 2003\Tools\Macros\Security\Security level </technical_mechanism>
        <technical_mechanism>(4)  HKCU\Software\Policies\Microsoft\Office\11.0\Excel\Security - Level</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1571</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1721-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Excel: Trust all installed add – ins and templates" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2003\Security Settings\Excel: Trust all installed add – ins and templates </technical_mechanism>
        <technical_mechanism>(2)  HKLM\Software\Policies\Microsoft\Office\11.0\Excel\Security - DontTrustInstalledFiles </technical_mechanism>
        <technical_mechanism>(3)  User Configuration\Administrative Templates\Microsoft Office Excel 2003\Tools\Macros\Security\Trust all installed add-ins and templates </technical_mechanism>
        <technical_mechanism>(4)  HKCU\Software\Policies\Microsoft\Office\11.0\Excel\Security - DontTrustInstalledFiles</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1721</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1602-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Outlook: Macro Security Level" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1)  1 = Enabled - Low | 2 = Enabled - Medium | 3 = Enabled - High</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2003\Security Settings\Outlook: Macro Security Level </technical_mechanism>
        <technical_mechanism>(2)  HKLM\Software\Policies\Microsoft\Office\11.0\Outlook\Security - Level </technical_mechanism>
        <technical_mechanism>(3)  User Configuration\Administrative Templates\Microsoft Office Outlook 2003\Tools\Macros\Security\Security Level </technical_mechanism>
        <technical_mechanism>(4)  HKCU\Software\Policies\Microsoft\Office\11.0\Outlook - Security\Level</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1602</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1624-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Outlook: Trust all installed add-ins and templates" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2003\Tools\Macros\Security\Outlook: Trust all installed add-ins and templates </technical_mechanism>
        <technical_mechanism>(2)  HKCU\Software\Policies\Microsoft\Office\11.0\Outlook\Security - DontTrustInstalledFiles</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1624</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1522-2' platform='office2k7' modified='2013-02-11'>
      <description>The "Outlook virus security settings" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1)  0 = Uses default administrative settings  |  1 = Look in the Outlook Security Settings folder  |  2 = Look in the Outlook 10 Security Settings folder</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2003\Tools\Options\Security\Outlook virus security settings </technical_mechanism>
        <technical_mechanism>(2)  HKCU\Software\Policies\Microsoft\Security - CheckAdminSettings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1522</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1183-3' platform='office2k7' modified='2013-02-11'>
      <description>The "S/MIME receipt requests" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1)  0 = Open message if receipt can't be sent | 1 = Always prompt before sending receipt | 2 = Never send S/MIME receipts | 3 = Don't open message if receipt can't be sent</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Outlook 2003\Tools\Options\Security\Cryptography\S/MIME receipt requests </technical_mechanism>
        <technical_mechanism>(2)  HKCU\Software\Policies\Microsoft\Office\11.0\Outlook\Security - RespondToReceiptRequests</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1183</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1611-3' platform='office2k7' modified='2013-02-11'>
      <description>The "PowerPoint: Macro Security Level" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1)  1 = Enabled - Low | 2 = Enabled - Medium | 3 = Enabled - High</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2003\Security Settings\PowerPoint: Macro Security Level </technical_mechanism>
        <technical_mechanism>(2)  HKLM\Software\Policies\Microsoft\Office\11.0\PowerPoint\Security - Level </technical_mechanism>
        <technical_mechanism>(3)  User Configuration\Administrative Templates\Microsoft Office PowerPoint 2003\Tools\Macro\Security\Security Level </technical_mechanism>
        <technical_mechanism>(4)  HKCU\Software\Policies\Microsoft\Office\11.0\PowerPoint - Security\Level</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1611</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1633-7' platform='office2k7' modified='2013-02-11'>
      <description>The "PowerPoint: Trust all installed add – ins and templates" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2003\Security Settings\PowerPoint: Trust all installed add – ins and templates </technical_mechanism>
        <technical_mechanism>(2)  HKLM\Software\Policies\Microsoft\Office\11.0\PowerPoint\Security - DontTrustInstalledFiles </technical_mechanism>
        <technical_mechanism>(3)  User Configuration\Administrative Templates\Microsoft Office PowerPoint 2003\Tools\Macro\Security\Trust all installed add – ins and templates </technical_mechanism>
        <technical_mechanism>(4)  HKCU\Software\Policies\Microsoft\Office\11.0\PowerPoint\Security - DontTrustInstalledFiles</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1633</reference>
      </references>
    </cce>
    <cce cce_id='CCE-822-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Publisher:  Macro Security Level" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1)  1 = Enabled - Low | 2 = Enabled - Medium | 3 = Enabled - High</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2003\Security Settings\Publisher:  Macro Security Level </technical_mechanism>
        <technical_mechanism>(2)  HKLM\Software\Policies\Microsoft\Office\11.0\Publisher\Security - Level</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-822</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1734-3' platform='office2k7' modified='2013-02-11'>
      <description>The "Publisher: Trust all installed add–ins and templates" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2003\Security Settings\Publisher: Trust all installed add–ins and templates </technical_mechanism>
        <technical_mechanism>(2)  HKLM\Software\Policies\Microsoft\Office\11.0\Publisher\Security - DontTrustInstalledFiles</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1734</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1628-7' platform='office2k7' modified='2013-02-11'>
      <description>The "Word: Macro Security Level" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1)  1 = Enabled - Low | 2 = Enabled - Medium | 3 = Enabled - High</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2003\Security Settings\Word: Macro Security Level </technical_mechanism>
        <technical_mechanism>(2)  HKLM\Software\Policies\Microsoft\Office\11.0\Word\Security - Level </technical_mechanism>
        <technical_mechanism>(3)  User Configuration\Administrative Templates\Microsoft Office Word 2003\Tools\Macro\Security\Security Level </technical_mechanism>
        <technical_mechanism>(4)  HKCU\Software\Policies\Microsoft\Office\11.0\Word - Security\Level</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1628</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1761-6' platform='office2k7' modified='2013-02-11'>
      <description>The "Word: Trust all installed add–ins and templates" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) Computer Configuration\Administrative Templates\Microsoft Office 2003\Security Settings\Word: Trust all installed add–ins and templates </technical_mechanism>
        <technical_mechanism>(2)  HKLM\Software\Policies\Microsoft\Office\11.0\Word\Security - DontTrustInstalledFiles </technical_mechanism>
        <technical_mechanism>(3)  User Configuration\Administrative Templates\Microsoft Office Word 2003\Tools\Macro\Security\Trust all installed add – ins and templates </technical_mechanism>
        <technical_mechanism>(4)  HKCU\Software\Policies\Microsoft\Office\11.0\Word\Security - DontTrustInstalledFiles</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1761</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1302-9' platform='office2k7' modified='2013-02-11'>
      <description>The "Store random number to improve merge accuracy" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office Word 2003\Tools\Options\Security\Store random number to improve merge accuracy </technical_mechanism>
        <technical_mechanism>(2)  HKCU\Software\Policies\Microsoft\Office\11.0\Word\Options\vpref - fDontSaveRSID_1804_1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1302</reference>
      </references>
    </cce>
    <cce cce_id='CCE-1307-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Prevent Users from Changing Office Encryption Settings" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Microsoft Office 2003\Security Settings\Prevent Users from Changing Office Encryption Settings </technical_mechanism>
        <technical_mechanism>(2)  HKCU\Software\Policies\Microsoft\Office\11.0\Common\Security - DisableCustomEncryption</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Old v4 CCE ID'>CCE-1307</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4277-0' platform='office2k7' modified='2013-02-11'>
      <description>The "Disable Update Diagnostics" setting should be configured correctly.</description>
      <parameters>
        <parameter>(1) 0 = Disabled | 1 = Enabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1)Computer Configuration\Administrative Templates\Classic Administrative Templates (ADM)\Microsoft Office 2007 system\Office Diagnostics\Disable Update Diagnostics (2) HKLM\Software\Policies\Microsoft\Office\Common\OffDiag\DisableOffDiagnostics</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>Computer Configuration\Administrative Templates\Classic Administrative Templates (ADM)\Microsoft Office 2007 system\Office Diagnostics\Disable Update Diagnostics</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4280-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Allow Active X One Off Forms" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) 0 = Enabled (Load only Outlook Controls) | 1 = Enabled (Allows only Safe Controls) | 2 = Enabled (Allows all ActiveX Controls)</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Classic Administrative Templates\Microsoft Office Outlook 2007\Security\Allow Active X One Off Forms (2) HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security\AllowActiveXOneOffForms</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Classic Administrative Templates\Microsoft Office Outlook 2007\Security\Allow Active X One Off Forms</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4283-8' platform='office2k7' modified='2013-02-11'>
      <description>The "Allow access to e-mail attachments" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) 0 = Disabled | 1 = Enabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Classic Administrative Templates\Microsoft Office Outlook 2007\Security\Allow access to e-mail attachments (2) HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security\Level1Add</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Classic Administrative Templates\Microsoft Office Outlook 2007\Security\Allow access to e-mail attachments</reference>
      </references>
    </cce>
    <cce cce_id='CCE-5276-1' platform='office2k7' modified='2013-02-11'>
      <description>The "Do not automatically sign replies" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>0 = Disabled | 1 = Enabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Classic Administrative Templates\Microsoft Office Outlook 2007\Security\Do not automatically sign replies (2) HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security\NoSignOnReply</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Classic Administrative Templates\Microsoft Office Outlook 2007\Security\Do not automatically sign replies</reference>
      </references>
    </cce>
    <cce cce_id='CCE-4440-4' platform='office2k7' modified='2013-02-11'>
      <description>The "Prompt user to choose security settings if default settings fail" setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>(1) 0 = Disabled | 1 = Enabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Classic Administrative Templates\Microsoft Office Outlook 2007\Security\Prompt user to choose security settings if default settings fail (2) HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security\ForceDefaultProfile</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Office 2007 Recommendations (Security Settings for Office 2007 Applications.xlsx)'>User Configuration\Administrative Templates\Classic Administrative Templates\Microsoft Office Outlook 2007\Security\Prompt user to choose security settings if default settings fail</reference>
      </references>
    </cce>
    <cce cce_id='CCE-19659-2' platform='office2k7' modified='2013-02-11'>
      <description>“Configure trusted add-ins” setting should be configured correctly for Outlook 2007.</description>
      <parameters>
        <parameter>Enabled | Disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>(1) User Configuration\Administrative Templates\Classic Administrative Templates\Microsoft Office Outlook 2007\Security\Security Form Settings\Programmatic Security\Trusted Add-ins </technical_mechanism>
        <technical_mechanism>(2) HKCU\Software\Policies\Microsoft\Office\12.0\Outlook\Security\TrustedAddins</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Office 2007 DISA STIGs'>STIG ID: DTOO256 - Outlook Rule ID: SV-18689r2_rule Vuln ID: V-17575: Configure trusted add-ins behavior for eMail.</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12740-7' platform='office2010' modified='2013-02-11'>
      <description>The "Default file location" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Save\Default file location</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\recentfolderlist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14442-8' platform='office2010' modified='2013-02-11'>
      <description>The "Suppress file format compatibility dialog box for OpenDocument Presentation format" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Save\Suppress file format compatibility dialog box for OpenDocument Presentation format</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13502-0' platform='office2010' modified='2013-02-11'>
      <description>The "Keep the last AutoSaved versions of files for the next session" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Save\Keep the last AutoSaved versions of files for the next session</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14536-7' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Package For CD" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Save\Disable Package For CD</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12518-7' platform='office2010' modified='2013-02-11'>
      <description>The "Default file format" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Save\Default file format</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14211-7' platform='office2010' modified='2013-02-11'>
      <description>The "Save AutoRecover info" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Save\Save AutoRecover info</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14709-0' platform='office2010' modified='2013-02-11'>
      <description>The "Disable commands" SharePoint Designer setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft SharePoint Designer 2010\Disable Items in User Interface\Predefined\Disable commands</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\sharepoint designer\disabledcmdbaritemscheckboxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13391-8' platform='office2010' modified='2013-02-11'>
      <description>The "Disable commands" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Disable Items in User Interface\Predefined\Disable commands</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\disabledcmdbaritemscheckboxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13995-6' platform='office2010' modified='2013-02-11'>
      <description>The "Disable shortcut keys" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Disable Items in User Interface\Predefined\Disable shortcut keys</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\disabledshortcutkeyscheckboxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12301-8' platform='office2010' modified='2013-02-11'>
      <description>The "Places Bar Location 6" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\File Open/Save dialog box\Places Bar Locations\Places Bar Location 6</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\open find\adminaddedplaces\place5</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12827-2' platform='office2010' modified='2013-02-11'>
      <description>The "Places Bar Location 5" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\File Open/Save dialog box\Places Bar Locations\Places Bar Location 5</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\open find\adminaddedplaces\place4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12268-9' platform='office2010' modified='2013-02-11'>
      <description>The "Places Bar Location 7" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\File Open/Save dialog box\Places Bar Locations\Places Bar Location 7</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\open find\adminaddedplaces\place6</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13788-5' platform='office2010' modified='2013-02-11'>
      <description>The "Places Bar Location 3" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\File Open/Save dialog box\Places Bar Locations\Places Bar Location 3</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\open find\adminaddedplaces\place2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14116-8' platform='office2010' modified='2013-02-11'>
      <description>The "Places Bar Location 8" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\File Open/Save dialog box\Places Bar Locations\Places Bar Location 8</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\open find\adminaddedplaces\place7</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14664-7' platform='office2010' modified='2013-02-11'>
      <description>The "Places Bar Location 1" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\File Open/Save dialog box\Places Bar Locations\Places Bar Location 1</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\open find\adminaddedplaces\place0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13104-5' platform='office2010' modified='2013-02-11'>
      <description>The "Places Bar Location 9" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\File Open/Save dialog box\Places Bar Locations\Places Bar Location 9</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\open find\adminaddedplaces\place8</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12670-6' platform='office2010' modified='2013-02-11'>
      <description>The "Places Bar Location 4" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\File Open/Save dialog box\Places Bar Locations\Places Bar Location 4</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\open find\adminaddedplaces\place3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14216-6' platform='office2010' modified='2013-02-11'>
      <description>The "Places Bar Location 10" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\File Open/Save dialog box\Places Bar Locations\Places Bar Location 10</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\open find\adminaddedplaces\place9</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13821-4' platform='office2010' modified='2013-02-11'>
      <description>The "Places Bar Location 2" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\File Open/Save dialog box\Places Bar Locations\Places Bar Location 2</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\open find\adminaddedplaces\place1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14642-3' platform='office2010' modified='2013-02-11'>
      <description>The "Project Guide Functionality and Layout page" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Interface\Project Guide settings for 'Project1'\Project Guide Functionality and Layout page</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\interface</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14182-0' platform='office2010' modified='2013-02-11'>
      <description>The "Project Guide Content" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Interface\Project Guide settings for 'Project1'\Project Guide Content</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\interface</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12439-6' platform='office2010' modified='2013-02-11'>
      <description>The "Do not show data extraction options when opening corrupt workbooks" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Data Recovery\Do not show data extraction options when opening corrupt workbooks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12954-4' platform='office2010' modified='2013-02-11'>
      <description>The "Scroll Bars" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\View\Show\Scroll Bars</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\view</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12684-7' platform='office2010' modified='2013-02-11'>
      <description>The "Windows in Taskbar" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\View\Show\Windows in Taskbar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\view</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14000-4' platform='office2010' modified='2013-02-11'>
      <description>The "Automatically add new items to the global project" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\View\Show\Automatically add new items to the global project</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\view</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13137-5' platform='office2010' modified='2013-02-11'>
      <description>The "Status Bar" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\View\Show\Status Bar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\view</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13379-3' platform='office2010' modified='2013-02-11'>
      <description>The "OLE Link Indicators" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\View\Show\OLE Link Indicators</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\view</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13422-1' platform='office2010' modified='2013-02-11'>
      <description>The "Project Screentips" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\View\Show\Project Screentips</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\view</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14898-1' platform='office2010' modified='2013-02-11'>
      <description>The "Entry Bar" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\View\Show\Entry Bar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\view</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12694-6' platform='office2010' modified='2013-02-11'>
      <description>The "Configure fast shutdown behavior for add-ins" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Miscellaneous\Miscellaneous\Configure fast shutdown behavior for add-ins</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\shutdown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14753-8' platform='office2010' modified='2013-02-11'>
      <description>The "Configure fast shutdown behavior" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Miscellaneous\Miscellaneous\Configure fast shutdown behavior</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\shutdown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13326-4' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent shutdown if external references exist" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Miscellaneous\Miscellaneous\Prevent shutdown if external references exist</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\shutdown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12263-0' platform='office2010' modified='2013-02-11'>
      <description>The "Set query items limit" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Business Data\Synchronization\Set query items limit</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\business data\synchronization</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14648-0' platform='office2010' modified='2013-02-11'>
      <description>The "Set subscription refresh retry interval" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Business Data\Synchronization\Set subscription refresh retry interval</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\business data\synchronization</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13913-9' platform='office2010' modified='2013-02-11'>
      <description>The "Set maximum number of retries when synchronization fails" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Business Data\Synchronization\Set maximum number of retries when synchronization fails</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\business data\synchronization</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11838-0' platform='office2010' modified='2013-02-11'>
      <description>The "Set errors cleanup interval" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Business Data\Synchronization\Set errors cleanup interval</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\business data\synchronization</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12076-6' platform='office2010' modified='2013-02-11'>
      <description>The "Set refresh frequency limit" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Business Data\Synchronization\Set refresh frequency limit</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\business data\synchronization</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12431-3' platform='office2010' modified='2013-02-11'>
      <description>The "Set maximum sleep interval" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Business Data\Synchronization\Set maximum sleep interval</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\business data\synchronization</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14603-5' platform='office2010' modified='2013-02-11'>
      <description>The "Set the cleanup interval" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Business Data\Synchronization\Set the cleanup interval</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\business data\synchronization</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13339-7' platform='office2010' modified='2013-02-11'>
      <description>The "Set query processing timeout limit" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Business Data\Synchronization\Set query processing timeout limit</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\business data\synchronization</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14469-1' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Trust Bar Notification for unsigned application add-ins" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Security\Trust Center\Disable Trust Bar Notification for unsigned application add-ins</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14062-4' platform='office2010' modified='2013-02-11'>
      <description>The "Disable all application add-ins" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Security\Trust Center\Disable all application add-ins</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13173-0' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Data Execution Prevention" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Security\Trust Center\Turn off Data Execution Prevention</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12930-4' platform='office2010' modified='2013-02-11'>
      <description>The "Block cross-domain data form retrieval" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Security\Trust Center\Block cross-domain data form retrieval</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14318-0' platform='office2010' modified='2013-02-11'>
      <description>The "Require that application add-ins are signed by Trusted Publisher" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Security\Trust Center\Require that application add-ins are signed by Trusted Publisher</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12900-7' platform='office2010' modified='2013-02-11'>
      <description>The "Disable all trusted locations" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Security\Trust Center\Disable all trusted locations</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security\trusted locations</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14388-3' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off file synchronization via SOAP over HTTP" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Miscellaneous\Server Settings\Turn off file synchronization via SOAP over HTTP</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13407-2' platform='office2010' modified='2013-02-11'>
      <description>The "Insertions color" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Track changes and compare\Insertions color</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11640-0' platform='office2010' modified='2013-02-11'>
      <description>The "Table compare colors" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Track changes and compare\Table compare colors</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14418-8' platform='office2010' modified='2013-02-11'>
      <description>The "Balloons" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Track changes and compare\Balloons</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14294-3' platform='office2010' modified='2013-02-11'>
      <description>The "Deletions color" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Track changes and compare\Deletions color</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12261-4' platform='office2010' modified='2013-02-11'>
      <description>The "Compare resulting document" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Track changes and compare\Compare resulting document</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13210-0' platform='office2010' modified='2013-02-11'>
      <description>The "Ignore White Space" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Track changes and compare\Ignore White Space</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14762-9' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Outlook send email to OneNote option" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Send to OneNote\Disable Outlook send email to OneNote option</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\outlookandweb</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12847-0' platform='office2010' modified='2013-02-11'>
      <description>The "Offline data cached per form template" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath Options\Advanced\Offline\Offline data cached per form template</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\editor\offline</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13583-0' platform='office2010' modified='2013-02-11'>
      <description>The "Offline Mode cache size" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath Options\Advanced\Offline\Offline Mode cache size</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\editor\offline</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14778-5' platform='office2010' modified='2013-02-11'>
      <description>The "Offline Mode status" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath Options\Advanced\Offline\Offline Mode status</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\editor\offline</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13852-9' platform='office2010' modified='2013-02-11'>
      <description>The "Include new rows and columns in table" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Proofing\Autocorrect Options\Include new rows and columns in table</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14307-3' platform='office2010' modified='2013-02-11'>
      <description>The "Internet and network paths as hyperlinks" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Proofing\Autocorrect Options\Internet and network paths as hyperlinks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13893-3' platform='office2010' modified='2013-02-11'>
      <description>The "Hyperlink color" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Web Options...\General\Hyperlink color</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11891-9' platform='office2010' modified='2013-02-11'>
      <description>The "Underline hyperlinks" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Web Options...\General\Underline hyperlinks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12063-4' platform='office2010' modified='2013-02-11'>
      <description>The "Followed hyperlink color" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Web Options...\General\Followed hyperlink color</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13843-8' platform='office2010' modified='2013-02-11'>
      <description>The "Open last file on startup" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\General\General options for Microsoft Project\Open last file on startup</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13317-3' platform='office2010' modified='2013-02-11'>
      <description>The "Prompt for project info for new projects" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\General\General options for Microsoft Project\Prompt for project info for new projects</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12786-0' platform='office2010' modified='2013-02-11'>
      <description>The "Recently used file list (MRU)" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\General\General options for Microsoft Project\Recently used file list (MRU)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13871-9' platform='office2010' modified='2013-02-11'>
      <description>The "Set AutoFilter on for new projects" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\General\General options for Microsoft Project\Set AutoFilter on for new projects</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14003-8' platform='office2010' modified='2013-02-11'>
      <description>The "List of error messages to customize" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Customizable Error Messages\List of error messages to customize</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\customizablealerts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13416-3' platform='office2010' modified='2013-02-11'>
      <description>The "Disable user from setting personal site as default location" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Global Options\Customize\Shared Workspace\Disable user from setting personal site as default location</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\portal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12182-2' platform='office2010' modified='2013-02-11'>
      <description>The "Automatic Discovery" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Global Options\Customize\Shared Workspace\Automatic Discovery</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\sharepointtracking</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14134-1' platform='office2010' modified='2013-02-11'>
      <description>The "OLAP PivotTable User Defined Function (UDF) security setting" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Miscellaneous\OLAP PivotTable User Defined Function (UDF) security setting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12329-9' platform='office2010' modified='2013-02-11'>
      <description>The "Do not cache network files locally" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Miscellaneous\Do not cache network files locally</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12419-8' platform='office2010' modified='2013-02-11'>
      <description>The "Graph gallery path" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Miscellaneous\Graph gallery path</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\graph\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14578-9' platform='office2010' modified='2013-02-11'>
      <description>The "Enable four-digit year display" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Miscellaneous\Enable four-digit year display</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13845-3' platform='office2010' modified='2013-02-11'>
      <description>The "Set maximum number of trusted documents" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\Set maximum number of trusted documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\trusted documents</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14047-5' platform='office2010' modified='2013-02-11'>
      <description>The "Disable all application add-ins" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\Disable all application add-ins</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13607-7' platform='office2010' modified='2013-02-11'>
      <description>The "Set maximum number of trust records to preserve" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\Set maximum number of trust records to preserve</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\trusted documents</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12798-5' platform='office2010' modified='2013-02-11'>
      <description>The "Require that application add-ins are signed by Trusted Publisher" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\Require that application add-ins are signed by Trusted Publisher</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12426-3' platform='office2010' modified='2013-02-11'>
      <description>The "VBA Macro Notification Settings" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\VBA Macro Notification Settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13641-6' platform='office2010' modified='2013-02-11'>
      <description>The "Store macro in Personal Macro Workbook by default" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\Store macro in Personal Macro Workbook by default</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options\binaryoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12214-3' platform='office2010' modified='2013-02-11'>
      <description>The "Trust access to Visual Basic Project" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\Trust access to Visual Basic Project</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12673-0' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Trusted Documents on the network" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\Turn off Trusted Documents on the network</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\trusted documents</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12641-7' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Data Execution Prevention" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\Turn off Data Execution Prevention</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13761-2' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Trust Bar Notification for unsigned application add-ins and block them" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\Disable Trust Bar Notification for unsigned application add-ins and block them</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12179-8' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off trusted documents" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\Turn off trusted documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\trusted documents</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14869-2' platform='office2010' modified='2013-02-11'>
      <description>The "Show scheduling messages" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Schedule\Schedule options for Microsoft Project\Show scheduling messages</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\scheduling</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13818-0' platform='office2010' modified='2013-02-11'>
      <description>The "Show assignment units as" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Schedule\Schedule options for Microsoft Project\Show assignment units as</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\scheduling</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12623-5' platform='office2010' modified='2013-02-11'>
      <description>The "Primary Editing Language" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Primary Editing Language</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14486-5' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off CAD/DWG functionality" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Save\Turn off CAD/DWG functionality</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14507-8' platform='office2010' modified='2013-02-11'>
      <description>The "Set refresh time for Calendar information for the person name action" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Instant Messaging Integration\Set refresh time for Calendar information for the person name action</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\personamenu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12298-6' platform='office2010' modified='2013-02-11'>
      <description>The "Disable the Send Mail item in the person name actions menu." common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Instant Messaging Integration\Disable the Send Mail item in the person name actions menu.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\personamenu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12280-4' platform='office2010' modified='2013-02-11'>
      <description>The "Disable all person name actions menu items" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Instant Messaging Integration\Disable all person name actions menu items</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\personamenu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14106-9' platform='office2010' modified='2013-02-11'>
      <description>The "Disable the Manager item in the person name actions menu." common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Instant Messaging Integration\Disable the Manager item in the person name actions menu.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\personamenu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14756-1' platform='office2010' modified='2013-02-11'>
      <description>The "Disable the Office Location item in the person name actions menu." common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Instant Messaging Integration\Disable the Office Location item in the person name actions menu.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\personamenu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11839-8' platform='office2010' modified='2013-02-11'>
      <description>The "Disable the Messaging item in the person name actions menu." common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Instant Messaging Integration\Disable the Messaging item in the person name actions menu.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\personamenu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14066-5' platform='office2010' modified='2013-02-11'>
      <description>The "Disable the Phone Number item in the person name actions menu." common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Instant Messaging Integration\Disable the Phone Number item in the person name actions menu.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\personamenu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13378-5' platform='office2010' modified='2013-02-11'>
      <description>The "Disable the Registered Person item in the person name actions menu." common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Instant Messaging Integration\Disable the Registered Person item in the person name actions menu.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\personamenu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14713-2' platform='office2010' modified='2013-02-11'>
      <description>The "Disable the Free/Busy item in the person name actions menu." common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Instant Messaging Integration\Disable the Free/Busy item in the person name actions menu.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\personamenu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12935-3' platform='office2010' modified='2013-02-11'>
      <description>The "Disable person name actions for my messaging contacts in Word and Excel" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Instant Messaging Integration\Disable person name actions for my messaging contacts in Word and Excel</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\personamenu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11836-4' platform='office2010' modified='2013-02-11'>
      <description>The "Disable the Add/Open Outlook Contacts item in the person name actions menu." common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Instant Messaging Integration\Disable the Add/Open Outlook Contacts item in the person name actions menu.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\personamenu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13712-5' platform='office2010' modified='2013-02-11'>
      <description>The "Disable the Outlook Properties item in the person name actions menu." common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Instant Messaging Integration\Disable the Outlook Properties item in the person name actions menu.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\personamenu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13772-9' platform='office2010' modified='2013-02-11'>
      <description>The "Disable the Online Status item in the person name actions menu." common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Instant Messaging Integration\Disable the Online Status item in the person name actions menu.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\personamenu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12779-5' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Create Rule item in the person name actions menu." common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Instant Messaging Integration\Disable Create Rule item in the person name actions menu.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\personamenu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14453-5' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Internet Fax feature" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Services\Fax\Disable Internet Fax feature</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\services\fax</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14235-6' platform='office2010' modified='2013-02-11'>
      <description>The "Disallow custom cover sheet" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Services\Fax\Disallow custom cover sheet</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\services\fax</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12961-9' platform='office2010' modified='2013-02-11'>
      <description>The "Plain text options" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Mail Format\Internet Formatting\Plain text options</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\mailsettings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14117-6' platform='office2010' modified='2013-02-11'>
      <description>The "Outlook Rich Text options" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Mail Format\Internet Formatting\Outlook Rich Text options</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11893-5' platform='office2010' modified='2013-02-11'>
      <description>The "Warn before permanently deleting items" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\Advanced\Warn before permanently deleting items</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11978-4' platform='office2010' modified='2013-02-11'>
      <description>The "Minimize Outlook to the system tray" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\Advanced\Minimize Outlook to the system tray</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12865-2' platform='office2010' modified='2013-02-11'>
      <description>The "Do not allow Outlook object model scripts to run for shared folders" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\Advanced\Do not allow Outlook object model scripts to run for shared folders</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13380-1' platform='office2010' modified='2013-02-11'>
      <description>The "Use Unicode format when dragging e-mail message to file system" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\Advanced\Use Unicode format when dragging e-mail message to file system</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14303-2' platform='office2010' modified='2013-02-11'>
      <description>The "Save calendar sync conflicts" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\Advanced\Save calendar sync conflicts</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14044-2' platform='office2010' modified='2013-02-11'>
      <description>The "Turn on logging for all conflicts" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\Advanced\Turn on logging for all conflicts</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13934-5' platform='office2010' modified='2013-02-11'>
      <description>The "Save RSS conflicts" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\Advanced\Save RSS conflicts</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13039-3' platform='office2010' modified='2013-02-11'>
      <description>The "Enable mail logging (troubleshooting)" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\Advanced\Enable mail logging (troubleshooting)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14390-9' platform='office2010' modified='2013-02-11'>
      <description>The "Do not allow Outlook object model scripts to run for public folders" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\Advanced\Do not allow Outlook object model scripts to run for public folders</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13726-5' platform='office2010' modified='2013-02-11'>
      <description>The "Do not allow folders in non-default stores to be set as folder home pages" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\Advanced\Do not allow folders in non-default stores to be set as folder home pages</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14422-0' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent saving sync conflicts" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\Advanced\Prevent saving sync conflicts</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13968-3' platform='office2010' modified='2013-02-11'>
      <description>The "Configure CNG cipher chaining mode" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Security\Cryptography\Configure CNG cipher chaining mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13397-5' platform='office2010' modified='2013-02-11'>
      <description>The "Set CNG password spin count" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Security\Cryptography\Set CNG password spin count</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14130-9' platform='office2010' modified='2013-02-11'>
      <description>The "Set CNG cipher algorithm" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Security\Cryptography\Set CNG cipher algorithm</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13041-9' platform='office2010' modified='2013-02-11'>
      <description>The "Specify encryption compatibility" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Security\Cryptography\Specify encryption compatibility</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13600-2' platform='office2010' modified='2013-02-11'>
      <description>The "Set parameters for CNG context" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Security\Cryptography\Set parameters for CNG context</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13771-1' platform='office2010' modified='2013-02-11'>
      <description>The "Set CNG cipher key length" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Security\Cryptography\Set CNG cipher key length</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12980-9' platform='office2010' modified='2013-02-11'>
      <description>The "Specify CNG hash algorithm" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Security\Cryptography\Specify CNG hash algorithm</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13929-5' platform='office2010' modified='2013-02-11'>
      <description>The "Specify CNG random number generator algorithm" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Security\Cryptography\Specify CNG random number generator algorithm</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13340-5' platform='office2010' modified='2013-02-11'>
      <description>The "Specify CNG salt length" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Security\Cryptography\Specify CNG salt length</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13736-4' platform='office2010' modified='2013-02-11'>
      <description>The "Set Outlook object model custom actions execution prompt" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Security Form Settings\Custom Form Security\Set Outlook object model custom actions execution prompt</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14048-3' platform='office2010' modified='2013-02-11'>
      <description>The "Allow scripts in one-off Outlook forms" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Security Form Settings\Custom Form Security\Allow scripts in one-off Outlook forms</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11862-0' platform='office2010' modified='2013-02-11'>
      <description>The "AutoArchive Settings" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\AutoArchive\AutoArchive Settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13029-4' platform='office2010' modified='2013-02-11'>
      <description>The "Disable File|Archive" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\AutoArchive\Disable File|Archive</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14863-5' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent co-authoring" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\Collaboration Settings\Co-authoring\Prevent co-authoring</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\coauthoring</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12609-4' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Internal ID Matching" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Interface\Disable Internal ID Matching</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\interface</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12474-3' platform='office2010' modified='2013-02-11'>
      <description>The "Disable shortcut keys" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\Disable Items in User Interface\Custom\Disable shortcut keys</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\disabledshortcutkeyslist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14135-8' platform='office2010' modified='2013-02-11'>
      <description>The "Disable commands" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\Disable Items in User Interface\Custom\Disable commands</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\disabledcmdbaritemslist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12386-9' platform='office2010' modified='2013-02-11'>
      <description>The "Force selection of account before sending" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Mail\Compose Messages\Force selection of account before sending</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12130-1' platform='office2010' modified='2013-02-11'>
      <description>The "Default servers and data for Meeting Workspaces" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Meeting Workspace\Default servers and data for Meeting Workspaces</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\meetings\profile</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14154-9' platform='office2010' modified='2013-02-11'>
      <description>The "Disable user entries to server list" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Meeting Workspace\Disable user entries to server list</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\meetings\profile</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14395-8' platform='office2010' modified='2013-02-11'>
      <description>The "Do not display Meeting Workspace button on the Meeting Request form" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Meeting Workspace\Do not display Meeting Workspace button on the Meeting Request form</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\meetings\profile</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14389-1' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #8" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Trusted Location #8</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations\location8</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13140-9' platform='office2010' modified='2013-02-11'>
      <description>The "Allow Trusted Locations on the network" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Allow Trusted Locations on the network</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11969-3' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #13" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Trusted Location #13</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations\location13</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13628-3' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #1" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Trusted Location #1</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations\location1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14665-4' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #16" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Trusted Location #16</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations\location16</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13523-6' platform='office2010' modified='2013-02-11'>
      <description>The "Disable all trusted locations" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Disable all trusted locations</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12824-9' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #3" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Trusted Location #3</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations\location3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13812-3' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #19" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Trusted Location #19</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations\location19</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13625-9' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #17" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Trusted Location #17</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations\location17</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14623-3' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #4" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Trusted Location #4</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations\location4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12272-1' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #14" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Trusted Location #14</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations\location14</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12904-9' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #2" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Trusted Location #2</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations\location2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12744-9' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #18" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Trusted Location #18</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations\location18</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13764-6' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #6" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Trusted Location #6</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations\location6</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13599-6' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #15" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Trusted Location #15</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations\location15</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12434-7' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #11" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Trusted Location #11</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations\location11</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12836-3' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #10" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Trusted Location #10</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations\location10</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12867-8' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #5" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Trusted Location #5</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations\location5</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13106-0' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #12" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Trusted Location #12</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations\location12</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13411-4' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #7" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Trusted Location #7</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations\location7</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12450-3' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #20" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Trusted Location #20</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations\location20</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12327-3' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #9" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trusted Locations\Trusted Location #9</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted locations\location9</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11949-5' platform='office2010' modified='2013-02-11'>
      <description>The "Email message for 'Send To' commands" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Miscellaneous\Email message for 'Send To' commands</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13697-8' platform='office2010' modified='2013-02-11'>
      <description>The "Use sequence checking" Publisher setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Publisher 2010\Publisher Options\Complex scripts\Use sequence checking</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\publisher\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13005-4' platform='office2010' modified='2013-02-11'>
      <description>The "Default Publisher direction" Publisher setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Publisher 2010\Publisher Options\Complex scripts\Default Publisher direction</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\publisher\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13616-8' platform='office2010' modified='2013-02-11'>
      <description>The "Use type and replace" Publisher setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Publisher 2010\Publisher Options\Complex scripts\Use type and replace</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\publisher\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13744-8' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking for blank table rows and columns" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\File Tab\Check Accessibility\Stop checking for blank table rows and columns</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12459-4' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking for table header accessibility information" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\File Tab\Check Accessibility\Stop checking for table header accessibility information</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14240-6' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking for alt text accessibility information" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\File Tab\Check Accessibility\Stop checking for alt text accessibility information</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14101-0' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking for tables used for layout" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\File Tab\Check Accessibility\Stop checking for tables used for layout</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14551-6' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking for merged and split cells" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\File Tab\Check Accessibility\Stop checking for merged and split cells</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13488-2' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking to ensure hyperlink text is meaningful" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\File Tab\Check Accessibility\Stop checking to ensure hyperlink text is meaningful</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12048-5' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking for image watermarks" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\File Tab\Check Accessibility\Stop checking for image watermarks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13802-4' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking to ensure styles have been used frequently" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\File Tab\Check Accessibility\Stop checking to ensure styles have been used frequently</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13841-2' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking to ensure documents allow programmatic access" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\File Tab\Check Accessibility\Stop checking to ensure documents allow programmatic access</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13725-7' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking to ensure long documents use styles for structure" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\File Tab\Check Accessibility\Stop checking to ensure long documents use styles for structure</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13255-5' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking whether objects are floating" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\File Tab\Check Accessibility\Stop checking whether objects are floating</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13798-4' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking whether blank characters are used for formatting" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\File Tab\Check Accessibility\Stop checking whether blank characters are used for formatting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12647-4' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking to ensure heading styles do not skip style level" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\File Tab\Check Accessibility\Stop checking to ensure heading styles do not skip style level</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12033-7' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking to ensure headings are succinct" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\File Tab\Check Accessibility\Stop checking to ensure headings are succinct</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12102-0' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off automatic search index reconciliation" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Search Options\Turn off automatic search index reconciliation</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\search</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14560-7' platform='office2010' modified='2013-02-11'>
      <description>The "Do not display search results as the user types" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Search Options\Do not display search results as the user types</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\search</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13498-1' platform='office2010' modified='2013-02-11'>
      <description>The "Do not include the Online Archive in All Mail Item search" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Search Options\Do not include the Online Archive in All Mail Item search</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\search</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13575-6' platform='office2010' modified='2013-02-11'>
      <description>The "Change color used to highlight search matches" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Search Options\Change color used to highlight search matches</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\search</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13560-8' platform='office2010' modified='2013-02-11'>
      <description>The "Expand scope of searches" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Search Options\Expand scope of searches</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\search</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13785-1' platform='office2010' modified='2013-02-11'>
      <description>The "Do not display hit highlights in search results" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Search Options\Do not display hit highlights in search results</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\search</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12933-8' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent clear signed message and attachment indexing" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Search Options\Prevent clear signed message and attachment indexing</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\windows\windows search\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13717-4' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent installation prompts when Windows Desktop Search component is not present" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Search Options\Prevent installation prompts when Windows Desktop Search component is not present</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\search</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13263-9' platform='office2010' modified='2013-02-11'>
      <description>The "Open e-mail attachments in Full Screen Reading view" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\General\Open e-mail attachments in Full Screen Reading view</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13090-6' platform='office2010' modified='2013-02-11'>
      <description>The "Show Mini Toolbar on selection" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\General\Show Mini Toolbar on selection</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\toolbars\word</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13387-6' platform='office2010' modified='2013-02-11'>
      <description>The "Enable Live Preview" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\General\Enable Live Preview</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14961-7' platform='office2010' modified='2013-02-11'>
      <description>The "Specify CNG random number generator algorithm" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Security\Cryptography\Specify CNG random number generator algorithm</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13777-8' platform='office2010' modified='2013-02-11'>
      <description>The "Specify CNG salt length" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Security\Cryptography\Specify CNG salt length</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11827-3' platform='office2010' modified='2013-02-11'>
      <description>The "Set CNG cipher key length" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Security\Cryptography\Set CNG cipher key length</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12340-6' platform='office2010' modified='2013-02-11'>
      <description>The "Set parameters for CNG context" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Security\Cryptography\Set parameters for CNG context</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12589-8' platform='office2010' modified='2013-02-11'>
      <description>The "Specify CNG hash algorithm" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Security\Cryptography\Specify CNG hash algorithm</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13142-5' platform='office2010' modified='2013-02-11'>
      <description>The "Configure CNG cipher chaining mode" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Security\Cryptography\Configure CNG cipher chaining mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13866-9' platform='office2010' modified='2013-02-11'>
      <description>The "Set CNG password spin count" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Security\Cryptography\Set CNG password spin count</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14734-8' platform='office2010' modified='2013-02-11'>
      <description>The "Set CNG cipher algorithm" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Security\Cryptography\Set CNG cipher algorithm</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14864-3' platform='office2010' modified='2013-02-11'>
      <description>The "Always create backup copy" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Always create backup copy</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14872-6' platform='office2010' modified='2013-02-11'>
      <description>The "Show measurements in units of" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Show measurements in units of</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12306-7' platform='office2010' modified='2013-02-11'>
      <description>The "Prompt to update style" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Prompt to update style</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12527-8' platform='office2010' modified='2013-02-11'>
      <description>The "Print on front of the sheet for duplex printing" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Print on front of the sheet for duplex printing</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vprsu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12291-1' platform='office2010' modified='2013-02-11'>
      <description>The "Month names" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Month names</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12634-2' platform='office2010' modified='2013-02-11'>
      <description>The "Confirm file format conversion on open" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Confirm file format conversion on open</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12841-3' platform='office2010' modified='2013-02-11'>
      <description>The "Cursor movement" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Cursor movement</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13399-1' platform='office2010' modified='2013-02-11'>
      <description>The "Show control characters" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Show control characters</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13236-5' platform='office2010' modified='2013-02-11'>
      <description>The "Use draft font in Draft and Outline views" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Use draft font in Draft and Outline views</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12643-3' platform='office2010' modified='2013-02-11'>
      <description>The "Print pages in reverse order" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Print pages in reverse order</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vprsu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13943-6' platform='office2010' modified='2013-02-11'>
      <description>The "Enable click and type" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Enable click and type</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14360-2' platform='office2010' modified='2013-02-11'>
      <description>The "When selecting, automatically select entire word" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\When selecting, automatically select entire word</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13635-8' platform='office2010' modified='2013-02-11'>
      <description>The "Add control characters in Cut and Copy" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Add control characters in Cut and Copy</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11548-5' platform='office2010' modified='2013-02-11'>
      <description>The "English Word 6.0/95 documents" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\English Word 6.0/95 documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12453-7' platform='office2010' modified='2013-02-11'>
      <description>The "Add Bi-Directional Marks when saving Text files" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Add Bi-Directional Marks when saving Text files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12420-6' platform='office2010' modified='2013-02-11'>
      <description>The "Left scroll bar" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Left scroll bar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14542-5' platform='office2010' modified='2013-02-11'>
      <description>The "Automatically create drawing canvas when inserting AutoShapes" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Automatically create drawing canvas when inserting AutoShapes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13854-5' platform='office2010' modified='2013-02-11'>
      <description>The "Number of documents in the Recent Documents list" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Number of documents in the Recent Documents list</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\file mru</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12971-8' platform='office2010' modified='2013-02-11'>
      <description>The "Show vertical scroll bar" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Show vertical scroll bar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14732-2' platform='office2010' modified='2013-02-11'>
      <description>The "Numeral" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Numeral</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13624-2' platform='office2010' modified='2013-02-11'>
      <description>The "Use CTRL + Click to follow hyperlink" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Use CTRL + Click to follow hyperlink</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13413-0' platform='office2010' modified='2013-02-11'>
      <description>The "Print in background" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Print in background</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11766-3' platform='office2010' modified='2013-02-11'>
      <description>The "Show vertical ruler in Print Layout view" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Show vertical ruler in Print Layout view</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13060-9' platform='office2010' modified='2013-02-11'>
      <description>The "Allow text to be dragged and dropped" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Allow text to be dragged and dropped</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13202-7' platform='office2010' modified='2013-02-11'>
      <description>The "Set number of places in the Recent Places list" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Set number of places in the Recent Places list</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\place mru</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13201-9' platform='office2010' modified='2013-02-11'>
      <description>The "Typing replaces selected text" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Typing replaces selected text</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14111-9' platform='office2010' modified='2013-02-11'>
      <description>The "Type and replace" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Type and replace</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14133-3' platform='office2010' modified='2013-02-11'>
      <description>The "Show horizontal scroll bar" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Show horizontal scroll bar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14371-9' platform='office2010' modified='2013-02-11'>
      <description>The "Auto-Keyboard switching" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Auto-Keyboard switching</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13001-3' platform='office2010' modified='2013-02-11'>
      <description>The "IME Control Active" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\IME Control Active</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12890-0' platform='office2010' modified='2013-02-11'>
      <description>The "Mark formatting inconsistencies" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Mark formatting inconsistencies</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\shared tools\proofing tools</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14115-0' platform='office2010' modified='2013-02-11'>
      <description>The "Add double quote for Hebrew alphabet numbering" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Add double quote for Hebrew alphabet numbering</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12777-9' platform='office2010' modified='2013-02-11'>
      <description>The "Asian fonts also apply to Latin text" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Asian fonts also apply to Latin text</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11503-0' platform='office2010' modified='2013-02-11'>
      <description>The "Show field codes instead of their values" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Show field codes instead of their values</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12492-5' platform='office2010' modified='2013-02-11'>
      <description>The "Show pixels for HTML features" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Show pixels for HTML features</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12416-4' platform='office2010' modified='2013-02-11'>
      <description>The "Use this color for diacritics" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Use this color for diacritics</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13451-0' platform='office2010' modified='2013-02-11'>
      <description>The "Use smart paragraph selection" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Use smart paragraph selection</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12344-8' platform='office2010' modified='2013-02-11'>
      <description>The "Show picture placeholders" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Show picture placeholders</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13043-5' platform='office2010' modified='2013-02-11'>
      <description>The "Keep track of formatting" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Keep track of formatting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13343-9' platform='office2010' modified='2013-02-11'>
      <description>The "Allow background saves" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Allow background saves</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14622-5' platform='office2010' modified='2013-02-11'>
      <description>The "Provide feedback with animation" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Provide feedback with animation</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13692-9' platform='office2010' modified='2013-02-11'>
      <description>The "Update automatic links at Open" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Update automatic links at Open</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13669-7' platform='office2010' modified='2013-02-11'>
      <description>The "Use draft quality" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Use draft quality</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vprsu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13456-9' platform='office2010' modified='2013-02-11'>
      <description>The "Show all windows in the Taskbar" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Show all windows in the Taskbar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14419-6' platform='office2010' modified='2013-02-11'>
      <description>The "Show text boundaries" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Show text boundaries</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13476-7' platform='office2010' modified='2013-02-11'>
      <description>The "Style area pane width in Draft and Outline views" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Style area pane width in Draft and Outline views</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12133-5' platform='office2010' modified='2013-02-11'>
      <description>The "Diacritics" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Diacritics</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11783-8' platform='office2010' modified='2013-02-11'>
      <description>The "Show measurements in width of characters" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Show measurements in width of characters</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12443-8' platform='office2010' modified='2013-02-11'>
      <description>The "Scale content for A4 or 8.5'' x 11'' paper sizes" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Scale content for A4 or 8.5'' x 11'' paper sizes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12546-8' platform='office2010' modified='2013-02-11'>
      <description>The "Document view" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Document view</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13322-3' platform='office2010' modified='2013-02-11'>
      <description>The "Cursor visual selection" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Cursor visual selection</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13698-6' platform='office2010' modified='2013-02-11'>
      <description>The "Copy remotely stored files onto your computer, and update the remote file when saving" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Copy remotely stored files onto your computer, and update the remote file when saving</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13032-8' platform='office2010' modified='2013-02-11'>
      <description>The "IME TrueInLine" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\IME TrueInLine</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14806-4' platform='office2010' modified='2013-02-11'>
      <description>The "Show text wrapped within the document window" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Show text wrapped within the document window</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13848-7' platform='office2010' modified='2013-02-11'>
      <description>The "Field shading" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Field shading</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12418-0' platform='office2010' modified='2013-02-11'>
      <description>The "Allow accented uppercase in French" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Allow accented uppercase in French</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11523-8' platform='office2010' modified='2013-02-11'>
      <description>The "Show text animation" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Show text animation</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12764-7' platform='office2010' modified='2013-02-11'>
      <description>The "Show drawings and text boxes on screen" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Show drawings and text boxes on screen</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12341-4' platform='office2010' modified='2013-02-11'>
      <description>The "Print on back of the sheet for duplex printing" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Print on back of the sheet for duplex printing</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vprsu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13728-1' platform='office2010' modified='2013-02-11'>
      <description>The "Prompt before saving Normal template" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Prompt before saving Normal template</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14362-8' platform='office2010' modified='2013-02-11'>
      <description>The "Use the Insert key for paste" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Use the Insert key for paste</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12844-7' platform='office2010' modified='2013-02-11'>
      <description>The "Show bookmarks" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Show bookmarks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13916-2' platform='office2010' modified='2013-02-11'>
      <description>The "Use sequence checking" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Use sequence checking</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11644-2' platform='office2010' modified='2013-02-11'>
      <description>The "Disable commands" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Disable Items in User Interface\Custom\Disable commands</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\disabledcmdbaritemslist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12198-8' platform='office2010' modified='2013-02-11'>
      <description>The "Disable shortcut keys" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Disable Items in User Interface\Custom\Disable shortcut keys</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\disabledshortcutkeyslist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12509-6' platform='office2010' modified='2013-02-11'>
      <description>The "Enable Customer Experience Improvement Program" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Privacy\Trust Center\Enable Customer Experience Improvement Program</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13629-1' platform='office2010' modified='2013-02-11'>
      <description>The "Automatically receive small updates to improve reliability" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Privacy\Trust Center\Automatically receive small updates to improve reliability</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12238-2' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Opt-in Wizard on first run" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Privacy\Trust Center\Disable Opt-in Wizard on first run</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11538-6' platform='office2010' modified='2013-02-11'>
      <description>The "Calculate all open projects" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calculation\Calculation options for Microsoft Project\Calculate all open projects</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calculation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14311-5' platform='office2010' modified='2013-02-11'>
      <description>The "Automatic Calculation" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calculation\Calculation options for Microsoft Project\Automatic Calculation</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calculation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12482-6' platform='office2010' modified='2013-02-11'>
      <description>The "Options" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Free/Busy Options\Options</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13801-6' platform='office2010' modified='2013-02-11'>
      <description>The "Internet Free/Busy Options" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Free/Busy Options\Internet Free/Busy Options</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\calendar\internet free/busy</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13787-7' platform='office2010' modified='2013-02-11'>
      <description>The "Disable shortcut keys" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Disable Items in User Interface\Custom\Disable shortcut keys</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\disabledshortcutkeyslist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14533-4' platform='office2010' modified='2013-02-11'>
      <description>The "Disable command bar buttons and menu items" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Disable Items in User Interface\Custom\Disable command bar buttons and menu items</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\disabledcmdbaritemslist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12645-8' platform='office2010' modified='2013-02-11'>
      <description>The "Store deleted items in owner's mailbox instead of delegate's mailbox" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Delegates\Store deleted items in owner's mailbox instead of delegate's mailbox</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13611-9' platform='office2010' modified='2013-02-11'>
      <description>The "Check for new actions URL" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Tools | AutoCorrect Options... (Excel, PowerPoint and Access)\Additional Actions\Check for new actions URL</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\smart tag</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14878-3' platform='office2010' modified='2013-02-11'>
      <description>The "Enable additional actions in Excel" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Tools | AutoCorrect Options... (Excel, PowerPoint and Access)\Additional Actions\Enable additional actions in Excel</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13702-6' platform='office2010' modified='2013-02-11'>
      <description>The "More actions URL" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Tools | AutoCorrect Options... (Excel, PowerPoint and Access)\Additional Actions\More actions URL</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\smart tag</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14286-9' platform='office2010' modified='2013-02-11'>
      <description>The "Graph gallery path" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Graph settings\Graph gallery path</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\graph\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12579-9' platform='office2010' modified='2013-02-11'>
      <description>The "Enable MS Graph as Default Chart Tool in PowerPoint and Word" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Graph settings\Enable MS Graph as Default Chart Tool in PowerPoint and Word</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\charting</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14194-5' platform='office2010' modified='2013-02-11'>
      <description>The "Chart Templates Server Location" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Graph settings\Chart Templates Server Location</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general\charttemplates</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13942-8' platform='office2010' modified='2013-02-11'>
      <description>The "Translation direction" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Review Tab\Chinese Conversion | Convert with Options\Translation direction</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\shared tools\proofing tools\tcsc translator</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12576-5' platform='office2010' modified='2013-02-11'>
      <description>The "Convert common terms" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Review Tab\Chinese Conversion | Convert with Options\Convert common terms</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\shared tools\proofing tools\tcsc translator</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12606-0' platform='office2010' modified='2013-02-11'>
      <description>The "Use Taiwan, Hong Kong SAR and Macao SAR character variants" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Review Tab\Chinese Conversion | Convert with Options\Use Taiwan, Hong Kong SAR and Macao SAR character variants</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\shared tools\proofing tools\tcsc translator</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14527-6' platform='office2010' modified='2013-02-11'>
      <description>The "Local Project Cache Location" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Tools | Local Project Cache\Local Project Cache Location</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14006-1' platform='office2010' modified='2013-02-11'>
      <description>The "Local Project Cache Size Limit in MB" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Tools | Local Project Cache\Local Project Cache Size Limit in MB</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13930-3' platform='office2010' modified='2013-02-11'>
      <description>The "Edit directly in cell" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Edit\Edit options for Microsoft Project\Edit directly in cell</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\edit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14565-6' platform='office2010' modified='2013-02-11'>
      <description>The "Allow cell drag and drop" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Edit\Edit options for Microsoft Project\Allow cell drag and drop</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\edit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14747-0' platform='office2010' modified='2013-02-11'>
      <description>The "Ask to update automatic links" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Edit\Edit options for Microsoft Project\Ask to update automatic links</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\edit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14097-0' platform='office2010' modified='2013-02-11'>
      <description>The "Move selection after enter" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Edit\Edit options for Microsoft Project\Move selection after enter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\edit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14067-3' platform='office2010' modified='2013-02-11'>
      <description>The "Set new tasks to be automatically scheduled" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Schedule\Scheduling options for 'Project1'\Set new tasks to be automatically scheduled</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\scheduling</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12586-4' platform='office2010' modified='2013-02-11'>
      <description>The "Tasks can be made inactive" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Schedule\Scheduling options for 'Project1'\Tasks can be made inactive</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\scheduling</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13443-7' platform='office2010' modified='2013-02-11'>
      <description>The "Autolink inserted or moved tasks" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Schedule\Scheduling options for 'Project1'\Autolink inserted or moved tasks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\scheduling</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13408-0' platform='office2010' modified='2013-02-11'>
      <description>The "Update manually scheduled tasks when editing links" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Schedule\Scheduling options for 'Project1'\Update manually scheduled tasks when editing links</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\scheduling</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12571-6' platform='office2010' modified='2013-02-11'>
      <description>The "New tasks are effort driven" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Schedule\Scheduling options for 'Project1'\New tasks are effort driven</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\scheduling</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14343-8' platform='office2010' modified='2013-02-11'>
      <description>The "New tasks" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Schedule\Scheduling options for 'Project1'\New tasks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\scheduling</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12030-3' platform='office2010' modified='2013-02-11'>
      <description>The "New tasks have estimated durations" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Schedule\Scheduling options for 'Project1'\New tasks have estimated durations</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\scheduling</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13696-0' platform='office2010' modified='2013-02-11'>
      <description>The "Tasks will always honor their constraint dates" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Schedule\Scheduling options for 'Project1'\Tasks will always honor their constraint dates</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\scheduling</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13805-7' platform='office2010' modified='2013-02-11'>
      <description>The "Default task type" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Schedule\Scheduling options for 'Project1'\Default task type</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\scheduling</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12461-0' platform='office2010' modified='2013-02-11'>
      <description>The "Keep tasks on nearest working day" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Schedule\Scheduling options for 'Project1'\Keep tasks on nearest working day</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\scheduling</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14774-4' platform='office2010' modified='2013-02-11'>
      <description>The "Show tasks schedule suggestions" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Schedule\Scheduling options for 'Project1'\Show tasks schedule suggestions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\scheduling</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11606-1' platform='office2010' modified='2013-02-11'>
      <description>The "Duration is entered in" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Schedule\Scheduling options for 'Project1'\Duration is entered in</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\scheduling</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14755-3' platform='office2010' modified='2013-02-11'>
      <description>The "Work is entered in" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Schedule\Scheduling options for 'Project1'\Work is entered in</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\scheduling</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12975-9' platform='office2010' modified='2013-02-11'>
      <description>The "Set default start date for new tasks" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Schedule\Scheduling options for 'Project1'\Set default start date for new tasks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\scheduling</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13122-7' platform='office2010' modified='2013-02-11'>
      <description>The "Show that tasks have estimated durations" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Schedule\Scheduling options for 'Project1'\Show that tasks have estimated durations</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\scheduling</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11775-4' platform='office2010' modified='2013-02-11'>
      <description>The "Show tasks schedule warnings" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Schedule\Scheduling options for 'Project1'\Show tasks schedule warnings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\scheduling</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14242-2' platform='office2010' modified='2013-02-11'>
      <description>The "Split in-progress tasks" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Schedule\Scheduling options for 'Project1'\Split in-progress tasks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\scheduling</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13590-5' platform='office2010' modified='2013-02-11'>
      <description>The "Function tooltips" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Function tooltips</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options\binaryoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14238-0' platform='office2010' modified='2013-02-11'>
      <description>The "Number of documents in the Recent Workbooks list" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Number of documents in the Recent Workbooks list</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\file mru</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12977-5' platform='office2010' modified='2013-02-11'>
      <description>The "Transition navigation keys" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Transition navigation keys</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options\binaryoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13781-0' platform='office2010' modified='2013-02-11'>
      <description>The "Edit directly in cell" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Edit directly in cell</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options\binaryoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13296-9' platform='office2010' modified='2013-02-11'>
      <description>The "Ask to update automatic links" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Ask to update automatic links</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options\binaryoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12761-3' platform='office2010' modified='2013-02-11'>
      <description>The "Alternate startup file location" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Alternate startup file location</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12404-0' platform='office2010' modified='2013-02-11'>
      <description>The "Show Formula bar in Full View" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Show Formula bar in Full View</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options\binaryoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14570-6' platform='office2010' modified='2013-02-11'>
      <description>The "Zoom on roll with IntelliMouse" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Zoom on roll with IntelliMouse</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options\binaryoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13064-1' platform='office2010' modified='2013-02-11'>
      <description>The "Microsoft Excel menu or Help key" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Microsoft Excel menu or Help key</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11994-1' platform='office2010' modified='2013-02-11'>
      <description>The "Show Insert Options buttons" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Show Insert Options buttons</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options\binaryoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12360-4' platform='office2010' modified='2013-02-11'>
      <description>The "Alert before overwriting cells" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Alert before overwriting cells</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options\binaryoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11528-7' platform='office2010' modified='2013-02-11'>
      <description>The "Default sheet direction" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Default sheet direction</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13979-0' platform='office2010' modified='2013-02-11'>
      <description>The "Show Formula bar in Normal View" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Show Formula bar in Normal View</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options\binaryoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11525-3' platform='office2010' modified='2013-02-11'>
      <description>The "Provide feedback with Animation" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Provide feedback with Animation</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options\binaryoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14083-0' platform='office2010' modified='2013-02-11'>
      <description>The "Show values" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Show values</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options\binaryoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14251-3' platform='office2010' modified='2013-02-11'>
      <description>The "Move selection after Enter direction" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Move selection after Enter direction</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12956-9' platform='office2010' modified='2013-02-11'>
      <description>The "Enable automatic percent entry" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Enable automatic percent entry</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options\binaryoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14726-4' platform='office2010' modified='2013-02-11'>
      <description>The "Extend data range formats and formulas" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Extend data range formats and formulas</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13549-1' platform='office2010' modified='2013-02-11'>
      <description>The "Enable AutoComplete for cell values" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Enable AutoComplete for cell values</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options\binaryoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12027-9' platform='office2010' modified='2013-02-11'>
      <description>The "Cursor movement" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Cursor movement</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12581-5' platform='office2010' modified='2013-02-11'>
      <description>The "Set number of places in the Recent Places list" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Set number of places in the Recent Places list</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\place mru</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13190-4' platform='office2010' modified='2013-02-11'>
      <description>The "Enable fill handle and cell drag-and-drop" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Enable fill handle and cell drag-and-drop</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options\binaryoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12470-1' platform='office2010' modified='2013-02-11'>
      <description>The "Ignore other applications" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Ignore other applications</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options\binaryoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13392-6' platform='office2010' modified='2013-02-11'>
      <description>The "Show names" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Show names</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options\binaryoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13835-4' platform='office2010' modified='2013-02-11'>
      <description>The "Comments" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Comments</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options\binaryoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12907-2' platform='office2010' modified='2013-02-11'>
      <description>The "Show control characters" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Show control characters</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12148-3' platform='office2010' modified='2013-02-11'>
      <description>The "Show Paste Options button when content is pasted" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Show Paste Options button when content is pasted</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13242-3' platform='office2010' modified='2013-02-11'>
      <description>The "Cut and copy objects with cells" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Cut and copy objects with cells</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options\binaryoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14973-2' platform='office2010' modified='2013-02-11'>
      <description>The "Automatically insert a decimal point" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Automatically insert a decimal point</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14817-1' platform='office2010' modified='2013-02-11'>
      <description>The "Move selection after Enter" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Advanced\Move selection after Enter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options\binaryoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13291-0' platform='office2010' modified='2013-02-11'>
      <description>The "Set maximum web service default timeout" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Business Data\Web Service\Set maximum web service default timeout</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\business data\limits\wcf\timeout</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13328-0' platform='office2010' modified='2013-02-11'>
      <description>The "Set maximum web service return size limit" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Business Data\Web Service\Set maximum web service return size limit</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\business data\limits\wcf\size</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13113-6' platform='office2010' modified='2013-02-11'>
      <description>The "Set web service default timeout" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Business Data\Web Service\Set web service default timeout</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\business data\limits\wcf\timeout</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13412-2' platform='office2010' modified='2013-02-11'>
      <description>The "Set web service default return size limit" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Business Data\Web Service\Set web service default return size limit</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\business data\limits\wcf\size</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11780-4' platform='office2010' modified='2013-02-11'>
      <description>The "Require SuiteB algorithms for S/MIME operations" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\Require SuiteB algorithms for S/MIME operations</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13256-3' platform='office2010' modified='2013-02-11'>
      <description>The "Fortezza certificate policies" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\Fortezza certificate policies</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14592-0' platform='office2010' modified='2013-02-11'>
      <description>The "Do not display 'Publish to GAL' button" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\Do not display 'Publish to GAL' button</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11740-8' platform='office2010' modified='2013-02-11'>
      <description>The "Sign all e-mail messages" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\Sign all e-mail messages</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14608-4' platform='office2010' modified='2013-02-11'>
      <description>The "Minimum encryption settings" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\Minimum encryption settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12486-7' platform='office2010' modified='2013-02-11'>
      <description>The "Enable Cryptography Icons" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\Enable Cryptography Icons</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12367-9' platform='office2010' modified='2013-02-11'>
      <description>The "Replies or forwards to signed/encrypted messages are signed/encrypted" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\Replies or forwards to signed/encrypted messages are signed/encrypted</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13095-5' platform='office2010' modified='2013-02-11'>
      <description>The "Always use TNEF formatting in S/MIME messages" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\Always use TNEF formatting in S/MIME messages</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12493-3' platform='office2010' modified='2013-02-11'>
      <description>The "Required Certificate Authority" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\Required Certificate Authority</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13280-3' platform='office2010' modified='2013-02-11'>
      <description>The "S/MIME interoperability with external clients:" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\S/MIME interoperability with external clients:</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13582-2' platform='office2010' modified='2013-02-11'>
      <description>The "Do not provide Continue option on Encryption warning dialog boxes" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\Do not provide Continue option on Encryption warning dialog boxes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14759-5' platform='office2010' modified='2013-02-11'>
      <description>The "Encrypt all e-mail messages" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\Encrypt all e-mail messages</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13073-2' platform='office2010' modified='2013-02-11'>
      <description>The "Send all signed messages as clear signed messages" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\Send all signed messages as clear signed messages</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12746-4' platform='office2010' modified='2013-02-11'>
      <description>The "Request an S/MIME receipt for all S/MIME signed messages" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\Request an S/MIME receipt for all S/MIME signed messages</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12276-2' platform='office2010' modified='2013-02-11'>
      <description>The "S/MIME receipt requests behavior" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\S/MIME receipt requests behavior</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14601-9' platform='office2010' modified='2013-02-11'>
      <description>The "Do not check e-mail address against address of certificates being used" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\Do not check e-mail address against address of certificates being used</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14381-8' platform='office2010' modified='2013-02-11'>
      <description>The "Ensure all S/MIME signed messages have a label" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\Ensure all S/MIME signed messages have a label</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13251-4' platform='office2010' modified='2013-02-11'>
      <description>The "Signature Warning" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\Signature Warning</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13967-5' platform='office2010' modified='2013-02-11'>
      <description>The "Run in FIPS compliant mode" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\Run in FIPS compliant mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12407-3' platform='office2010' modified='2013-02-11'>
      <description>The "URL for S/MIME certificates" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\URL for S/MIME certificates</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13383-5' platform='office2010' modified='2013-02-11'>
      <description>The "Message when Outlook cannot find the digital ID to decode a message" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\Message when Outlook cannot find the digital ID to decode a message</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14206-7' platform='office2010' modified='2013-02-11'>
      <description>The "Message Formats" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Cryptography\Message Formats</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12721-7' platform='office2010' modified='2013-02-11'>
      <description>The "Run Programs" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Run Programs</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12072-5' platform='office2010' modified='2013-02-11'>
      <description>The "Unblock automatic download of linked images" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Unblock automatic download of linked images</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13054-2' platform='office2010' modified='2013-02-11'>
      <description>The "Scan encrypted macros in PowerPoint Open XML presentations" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Scan encrypted macros in PowerPoint Open XML presentations</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12638-3' platform='office2010' modified='2013-02-11'>
      <description>The "Make hidden markup visible" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Make hidden markup visible</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13672-1' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off file validation" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Turn off file validation</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\filevalidation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13289-4' platform='office2010' modified='2013-02-11'>
      <description>The "List of error messages to customize" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Customizable Error Messages\List of error messages to customize</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\customizablealerts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14505-2' platform='office2010' modified='2013-02-11'>
      <description>The "Save new Web pages as Web archives" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Web Archives\Save new Web pages as Web archives</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12231-7' platform='office2010' modified='2013-02-11'>
      <description>The "Allow Web Archives to be saved in any HTML encoding" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Web Archives\Allow Web Archives to be saved in any HTML encoding</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13945-1' platform='office2010' modified='2013-02-11'>
      <description>The "Default format for 'Publish'" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Web Archives\Default format for 'Publish'</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14544-1' platform='office2010' modified='2013-02-11'>
      <description>The "PowerPoint:  web page format compatibility" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Web Archives\PowerPoint:  web page format compatibility</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14019-4' platform='office2010' modified='2013-02-11'>
      <description>The "PowerPoint: Save an additional version of the presentation for older browsers" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Web Archives\PowerPoint: Save an additional version of the presentation for older browsers</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14233-1' platform='office2010' modified='2013-02-11'>
      <description>The "Save multiple credentials for basic authentication" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\E-mail\Save multiple credentials for basic authentication</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14571-4' platform='office2010' modified='2013-02-11'>
      <description>The "Specify Offline Address Book path" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\E-mail\Specify Offline Address Book path</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\cached mode</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13889-1' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent saving credentials for Basic Authentication policy" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\E-mail\Prevent saving credentials for Basic Authentication policy</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12892-6' platform='office2010' modified='2013-02-11'>
      <description>The "Excel 2007 and later macro-enabled workbooks and templates" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Excel 2007 and later macro-enabled workbooks and templates</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14377-6' platform='office2010' modified='2013-02-11'>
      <description>The "Excel 2 worksheets" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Excel 2 worksheets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12135-0' platform='office2010' modified='2013-02-11'>
      <description>The "OpenDocument Spreadsheet files" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\OpenDocument Spreadsheet files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12938-7' platform='office2010' modified='2013-02-11'>
      <description>The "Excel 3 macrosheets and add-in files" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Excel 3 macrosheets and add-in files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14721-5' platform='office2010' modified='2013-02-11'>
      <description>The "Microsoft Office data connection files" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Microsoft Office data connection files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12882-7' platform='office2010' modified='2013-02-11'>
      <description>The "Web pages and Excel 2003 XML spreadsheets" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Web pages and Excel 2003 XML spreadsheets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14450-1' platform='office2010' modified='2013-02-11'>
      <description>The "Excel 95-97 workbooks and templates" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Excel 95-97 workbooks and templates</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12951-0' platform='office2010' modified='2013-02-11'>
      <description>The "Set default file block behavior" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Set default file block behavior</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13562-4' platform='office2010' modified='2013-02-11'>
      <description>The "dBase III / IV files" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\dBase III / IV files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14365-1' platform='office2010' modified='2013-02-11'>
      <description>The "Excel 2007 and later binary workbooks" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Excel 2007 and later binary workbooks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11549-3' platform='office2010' modified='2013-02-11'>
      <description>The "Excel 97-2003 add-in files" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Excel 97-2003 add-in files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14840-3' platform='office2010' modified='2013-02-11'>
      <description>The "Other data source files" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Other data source files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14760-3' platform='office2010' modified='2013-02-11'>
      <description>The "Offline cube files" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Offline cube files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13944-4' platform='office2010' modified='2013-02-11'>
      <description>The "Excel add-in files" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Excel add-in files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13478-3' platform='office2010' modified='2013-02-11'>
      <description>The "Microsoft Office query files" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Microsoft Office query files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14017-8' platform='office2010' modified='2013-02-11'>
      <description>The "Legacy converters for Excel" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Legacy converters for Excel</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12679-7' platform='office2010' modified='2013-02-11'>
      <description>The "Excel 95 workbooks" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Excel 95 workbooks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12605-2' platform='office2010' modified='2013-02-11'>
      <description>The "Microsoft Office Open XML converters for Excel" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Microsoft Office Open XML converters for Excel</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12870-2' platform='office2010' modified='2013-02-11'>
      <description>The "Excel 2007 and later add-in files" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Excel 2007 and later add-in files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13205-0' platform='office2010' modified='2013-02-11'>
      <description>The "Excel 4 worksheets" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Excel 4 worksheets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12920-5' platform='office2010' modified='2013-02-11'>
      <description>The "Text files" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Text files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14477-4' platform='office2010' modified='2013-02-11'>
      <description>The "XML files" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\XML files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12771-2' platform='office2010' modified='2013-02-11'>
      <description>The "Excel 4 macrosheets and add-in files" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Excel 4 macrosheets and add-in files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12590-6' platform='office2010' modified='2013-02-11'>
      <description>The "Excel 2007 and later workbooks and templates" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Excel 2007 and later workbooks and templates</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12560-9' platform='office2010' modified='2013-02-11'>
      <description>The "Excel 4 workbooks" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Excel 4 workbooks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12374-5' platform='office2010' modified='2013-02-11'>
      <description>The "Excel 97-2003 workbooks and templates" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Excel 97-2003 workbooks and templates</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12923-9' platform='office2010' modified='2013-02-11'>
      <description>The "Excel 2 macrosheets and add-in files" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Excel 2 macrosheets and add-in files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13238-1' platform='office2010' modified='2013-02-11'>
      <description>The "Dif and Sylk files" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Dif and Sylk files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13107-8' platform='office2010' modified='2013-02-11'>
      <description>The "Excel 3 worksheets" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\File Block Settings\Excel 3 worksheets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12600-3' platform='office2010' modified='2013-02-11'>
      <description>The "Allow mix of policy and user locations" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Allow mix of policy and user locations</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\trusted locations</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14136-6' platform='office2010' modified='2013-02-11'>
      <description>The "Enable connector splitting" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Editing Options\Enable connector splitting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12840-5' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off smart delete behavior of connectors when deleting shapes" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Editing Options\Turn off smart delete behavior of connectors when deleting shapes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12383-6' platform='office2010' modified='2013-02-11'>
      <description>The "Enable AutoConnect" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Editing Options\Enable AutoConnect</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13228-2' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off ShapeSheet Formula AutoComplete" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Editing Options\Turn off ShapeSheet Formula AutoComplete</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13958-4' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off transitions" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Editing Options\Turn off transitions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14001-2' platform='office2010' modified='2013-02-11'>
      <description>The "Enable live dynamics" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Editing Options\Enable live dynamics</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13621-8' platform='office2010' modified='2013-02-11'>
      <description>The "Center selection on zoom" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Editing Options\Center selection on zoom</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12397-6' platform='office2010' modified='2013-02-11'>
      <description>The "Zoom on roll with IntelliMouse" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Editing Options\Zoom on roll with IntelliMouse</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13176-3' platform='office2010' modified='2013-02-11'>
      <description>The "Show more handles on hover" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Editing Options\Show more handles on hover</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13981-6' platform='office2010' modified='2013-02-11'>
      <description>The "Select shapes partially within area" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Editing Options\Select shapes partially within area</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11676-4' platform='office2010' modified='2013-02-11'>
      <description>The "Save Microsoft Project files as" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Save\Save Microsoft Project files as</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\save</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13729-9' platform='office2010' modified='2013-02-11'>
      <description>The "Automatically add new resources and tasks" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\General\General options for 'Project1'\Automatically add new resources and tasks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12759-7' platform='office2010' modified='2013-02-11'>
      <description>The "Default overtime rate" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\General\General options for 'Project1'\Default overtime rate</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13178-9' platform='office2010' modified='2013-02-11'>
      <description>The "Default standard rate" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\General\General options for 'Project1'\Default standard rate</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14119-2' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off file synchronization via SOAP over HTTP" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Miscellaneous\Server Settings\Turn off file synchronization via SOAP over HTTP</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13662-2' platform='office2010' modified='2013-02-11'>
      <description>The "List of error messages to customize" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Customizable Error Messages\List of error messages to customize</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\customizablealerts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12535-1' platform='office2010' modified='2013-02-11'>
      <description>The "Message handling" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\E-mail Options\Message handling</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14293-5' platform='office2010' modified='2013-02-11'>
      <description>The "Do not use Conversation arrangement in Views" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\E-mail Options\Do not use Conversation arrangement in Views</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\setup</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12958-5' platform='office2010' modified='2013-02-11'>
      <description>The "Configure Cross Folder Content in conversation view" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\E-mail Options\Configure Cross Folder Content in conversation view</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\conversations</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13156-5' platform='office2010' modified='2013-02-11'>
      <description>The "Read e-mail as plain text" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\E-mail Options\Read e-mail as plain text</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14771-0' platform='office2010' modified='2013-02-11'>
      <description>The "On replies and forwards" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\E-mail Options\On replies and forwards</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\mailsettings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13248-0' platform='office2010' modified='2013-02-11'>
      <description>The "Do not allow attachment previewing in Outlook" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\E-mail Options\Do not allow attachment previewing in Outlook</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12098-0' platform='office2010' modified='2013-02-11'>
      <description>The "Change CTRL+ENTER shortcut behavior" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\E-mail Options\Change CTRL+ENTER shortcut behavior</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13694-5' platform='office2010' modified='2013-02-11'>
      <description>The "Read signed e-mail as plain text" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\E-mail Options\Read signed e-mail as plain text</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12868-6' platform='office2010' modified='2013-02-11'>
      <description>The "Set message format" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Mail Format\Internet Formatting\Message Format\Set message format</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13358-7' platform='office2010' modified='2013-02-11'>
      <description>The "Disable commands under File tab | Help" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Disable Items in User Interface\Disable commands under File tab | Help</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\disabledcmdbaritemscheckboxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14587-0' platform='office2010' modified='2013-02-11'>
      <description>The "Configure Outlook object model prompt when executing Save As" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Security Form Settings\Programmatic Security\Configure Outlook object model prompt when executing Save As</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14634-0' platform='office2010' modified='2013-02-11'>
      <description>The "Configure Outlook object model prompt when responding to meeting and task requests" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Security Form Settings\Programmatic Security\Configure Outlook object model prompt when responding to meeting and task requests</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14265-3' platform='office2010' modified='2013-02-11'>
      <description>The "Configure Outlook object model prompt When accessing the Formula property of a UserProperty object" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Security Form Settings\Programmatic Security\Configure Outlook object model prompt When accessing the Formula property of a UserProperty object</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12402-4' platform='office2010' modified='2013-02-11'>
      <description>The "Configure Outlook object model prompt when sending mail" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Security Form Settings\Programmatic Security\Configure Outlook object model prompt when sending mail</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14509-4' platform='office2010' modified='2013-02-11'>
      <description>The "Configure Outlook object model prompt when reading address information" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Security Form Settings\Programmatic Security\Configure Outlook object model prompt when reading address information</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12322-4' platform='office2010' modified='2013-02-11'>
      <description>The "Configure Outlook object model prompt when accessing an address book" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Security Form Settings\Programmatic Security\Configure Outlook object model prompt when accessing an address book</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14331-3' platform='office2010' modified='2013-02-11'>
      <description>The "Disable built-in graphics" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Microsoft Office SmartArt\Disable built-in graphics</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\smartart graphics</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13807-3' platform='office2010' modified='2013-02-11'>
      <description>The "Log File Entries Number" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Microsoft Office SmartArt\Log File Entries Number</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\smartart graphics</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14987-2' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Built-in Quick Styles" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Microsoft Office SmartArt\Disable Built-in Quick Styles</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\smartart graphics</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14783-5' platform='office2010' modified='2013-02-11'>
      <description>The "Log File Maximum Size" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Microsoft Office SmartArt\Log File Maximum Size</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\smartart graphics</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12713-4' platform='office2010' modified='2013-02-11'>
      <description>The "Disable built-in color variations" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Microsoft Office SmartArt\Disable built-in color variations</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\smartart graphics</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13831-3' platform='office2010' modified='2013-02-11'>
      <description>The "Error Severity Level" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Microsoft Office SmartArt\Error Severity Level</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\smartart graphics</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12425-5' platform='office2010' modified='2013-02-11'>
      <description>The "Configure CNG cipher chaining mode" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Cryptography\Configure CNG cipher chaining mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13310-8' platform='office2010' modified='2013-02-11'>
      <description>The "Set CNG cipher key length" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Cryptography\Set CNG cipher key length</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13984-0' platform='office2010' modified='2013-02-11'>
      <description>The "Set CNG password spin count" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Cryptography\Set CNG password spin count</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14021-0' platform='office2010' modified='2013-02-11'>
      <description>The "Specify CNG salt length" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Cryptography\Specify CNG salt length</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14396-6' platform='office2010' modified='2013-02-11'>
      <description>The "Specify encryption compatibility" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Cryptography\Specify encryption compatibility</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12454-5' platform='office2010' modified='2013-02-11'>
      <description>The "Specify CNG hash algorithm" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Cryptography\Specify CNG hash algorithm</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11887-7' platform='office2010' modified='2013-02-11'>
      <description>The "Set CNG cipher algorithm" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Cryptography\Set CNG cipher algorithm</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14546-6' platform='office2010' modified='2013-02-11'>
      <description>The "Use new key on password change" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Cryptography\Use new key on password change</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14289-3' platform='office2010' modified='2013-02-11'>
      <description>The "Set parameters for CNG context" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Cryptography\Set parameters for CNG context</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13350-4' platform='office2010' modified='2013-02-11'>
      <description>The "Specify CNG random number generator algorithm" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Cryptography\Specify CNG random number generator algorithm</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12749-8' platform='office2010' modified='2013-02-11'>
      <description>The "Save Messages" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\E-mail Options\Advanced E-mail Options\Save Messages</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12561-7' platform='office2010' modified='2013-02-11'>
      <description>The "When sending a message" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\E-mail Options\Advanced E-mail Options\When sending a message</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13704-2' platform='office2010' modified='2013-02-11'>
      <description>The "More save messages" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\E-mail Options\Advanced E-mail Options\More save messages</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12763-9' platform='office2010' modified='2013-02-11'>
      <description>The "When new items arrive" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\E-mail Options\Advanced E-mail Options\When new items arrive</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14792-6' platform='office2010' modified='2013-02-11'>
      <description>The "Do not allow e-mail postmark functionality" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\E-mail Options\Advanced E-mail Options\Do not allow e-mail postmark functionality</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13244-9' platform='office2010' modified='2013-02-11'>
      <description>The "Most Recently Used Template List Length" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Most Recently Used Template List Length</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13063-3' platform='office2010' modified='2013-02-11'>
      <description>The "Show Paste Options button when content is pasted" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Show Paste Options button when content is pasted</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11485-0' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Clipboard Toolbar triggers" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Disable Clipboard Toolbar triggers</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12943-7' platform='office2010' modified='2013-02-11'>
      <description>The "Print ticket safe mode" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Print ticket safe mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14096-2' platform='office2010' modified='2013-02-11'>
      <description>The "Set ScreenTip Language download location" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Set ScreenTip Language download location</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\uicaptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13862-8' platform='office2010' modified='2013-02-11'>
      <description>The "Disallow Convert Document (Excel, PowerPoint, Word)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Disallow Convert Document (Excel, PowerPoint, Word)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13092-2' platform='office2010' modified='2013-02-11'>
      <description>The "Disable web view in the Office file dialog boxes" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Disable web view in the Office file dialog boxes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\filedialogwebviewsettings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13925-3' platform='office2010' modified='2013-02-11'>
      <description>The "Enable Workflows on My Site" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Enable Workflows on My Site</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\workflow\home</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13158-1' platform='office2010' modified='2013-02-11'>
      <description>The "Increase the visibility of Accessibility Checker violations" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Increase the visibility of Accessibility Checker violations</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13749-7' platform='office2010' modified='2013-02-11'>
      <description>The "Show Screen Tips" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Show Screen Tips</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13711-7' platform='office2010' modified='2013-02-11'>
      <description>The "Do not validate printers before using them" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Do not validate printers before using them</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14163-0' platform='office2010' modified='2013-02-11'>
      <description>The "Control Blogging" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Control Blogging</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\blog</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12305-9' platform='office2010' modified='2013-02-11'>
      <description>The "Graphic filter legacy mode" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Graphic filter legacy mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\shared tools\graphics filters</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13803-2' platform='office2010' modified='2013-02-11'>
      <description>The "Do not allow Save to Web integration" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Do not allow Save to Web integration</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\webintegration</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14941-9' platform='office2010' modified='2013-02-11'>
      <description>The "Home Workflow Library" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Home Workflow Library</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\workflow\home</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12913-0' platform='office2010' modified='2013-02-11'>
      <description>The "Do not use hardware graphics acceleration" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Do not use hardware graphics acceleration</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\gfx</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11968-5' platform='office2010' modified='2013-02-11'>
      <description>The "Enable Smart Resume" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Enable Smart Resume</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\restore workspace</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12752-2' platform='office2010' modified='2013-02-11'>
      <description>The "Change destination URL for SharePoint hyperlink" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Change destination URL for SharePoint hyperlink</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\sharepointintegration</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13061-7' platform='office2010' modified='2013-02-11'>
      <description>The "Disable hyperlinks to web templates in File | New and task panes" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Disable hyperlinks to web templates in File | New and task panes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12084-0' platform='office2010' modified='2013-02-11'>
      <description>The "Hide the Learn more about SharePoint Hyperlink" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Hide the Learn more about SharePoint Hyperlink</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\sharepointintegration</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14583-9' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Microsoft Office shared drawing code for blip caching" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Disable Microsoft Office shared drawing code for blip caching</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\gelprefs</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13735-6' platform='office2010' modified='2013-02-11'>
      <description>The "Do not emulate tabs with spaces when exporting HTML" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Do not emulate tabs with spaces when exporting HTML</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11981-8' platform='office2010' modified='2013-02-11'>
      <description>The "Change label of Save to SharePoint" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Change label of Save to SharePoint</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\sharepointintegration</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14366-9' platform='office2010' modified='2013-02-11'>
      <description>The "Do not display paths in alerts" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Do not display paths in alerts</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12222-6' platform='office2010' modified='2013-02-11'>
      <description>The "Provide feedback with sound" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Provide feedback with sound</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12253-1' platform='office2010' modified='2013-02-11'>
      <description>The "Do not track document editing time" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Do not track document editing time</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13192-0' platform='office2010' modified='2013-02-11'>
      <description>The "Do not upload media files" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Do not upload media files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13956-8' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Microsoft Office shared drawing code for metafile rendering" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Disable Microsoft Office shared drawing code for metafile rendering</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\gelprefs</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13448-6' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent access to Web-based file storage" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Prevent access to Web-based file storage</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\webservices</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13820-6' platform='office2010' modified='2013-02-11'>
      <description>The "Undo Levels" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\General\Undo Levels</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13568-1' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #13" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Trusted Location #13</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations\location13</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13155-7' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #5" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Trusted Location #5</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations\location5</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11855-4' platform='office2010' modified='2013-02-11'>
      <description>The "Allow Trusted Locations on the network" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Allow Trusted Locations on the network</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14324-8' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #20" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Trusted Location #20</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations\location20</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13937-8' platform='office2010' modified='2013-02-11'>
      <description>The "Disable all trusted locations" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Disable all trusted locations</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13642-4' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #19" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Trusted Location #19</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations\location19</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12608-6' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #3" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Trusted Location #3</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations\location3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13021-1' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #16" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Trusted Location #16</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations\location16</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14789-2' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #7" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Trusted Location #7</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations\location7</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12675-5' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #4" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Trusted Location #4</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations\location4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12411-5' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #18" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Trusted Location #18</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations\location18</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14162-2' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #11" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Trusted Location #11</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations\location11</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12982-5' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #2" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Trusted Location #2</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations\location2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14221-6' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #10" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Trusted Location #10</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations\location10</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13693-7' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #12" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Trusted Location #12</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations\location12</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11480-1' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #15" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Trusted Location #15</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations\location15</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12731-6' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #6" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Trusted Location #6</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations\location6</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13690-3' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #8" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Trusted Location #8</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations\location8</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12400-8' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #17" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Trusted Location #17</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations\location17</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14740-5' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #1" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Trusted Location #1</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations\location1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12894-2' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #9" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Trusted Location #9</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations\location9</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13518-6' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #14" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Trusted Locations\Trusted Location #14</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted locations\location14</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14100-2' platform='office2010' modified='2013-02-11'>
      <description>The "Security Level" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Security\Tools | Macro\Security Level</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12498-2' platform='office2010' modified='2013-02-11'>
      <description>The "Specify CNG hash algorithm" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Cryptography\Specify CNG hash algorithm</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12726-6' platform='office2010' modified='2013-02-11'>
      <description>The "Specify encryption compatibility" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Cryptography\Specify encryption compatibility</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13902-2' platform='office2010' modified='2013-02-11'>
      <description>The "Set CNG cipher algorithm" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Cryptography\Set CNG cipher algorithm</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12782-9' platform='office2010' modified='2013-02-11'>
      <description>The "Specify CNG salt length" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Cryptography\Specify CNG salt length</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14295-0' platform='office2010' modified='2013-02-11'>
      <description>The "Set CNG cipher key length" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Cryptography\Set CNG cipher key length</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13584-8' platform='office2010' modified='2013-02-11'>
      <description>The "Set CNG password spin count" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Cryptography\Set CNG password spin count</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12986-6' platform='office2010' modified='2013-02-11'>
      <description>The "Set parameters for CNG context" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Cryptography\Set parameters for CNG context</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13608-5' platform='office2010' modified='2013-02-11'>
      <description>The "Specify CNG random number generator algorithm" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Cryptography\Specify CNG random number generator algorithm</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13721-6' platform='office2010' modified='2013-02-11'>
      <description>The "Configure CNG cipher chaining mode" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Cryptography\Configure CNG cipher chaining mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\crypto</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12167-3' platform='office2010' modified='2013-02-11'>
      <description>The "Disable commands" Publisher setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Publisher 2010\Disable Items in User Interface\Predefined\Disable commands</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\publisher\disabledcmdbaritemscheckboxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13293-6' platform='office2010' modified='2013-02-11'>
      <description>The "Overwrite or Append Junk Mail Import List" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Junk E-mail\Overwrite or Append Junk Mail Import List</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12916-3' platform='office2010' modified='2013-02-11'>
      <description>The "Specify path to Safe Recipients list" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Junk E-mail\Specify path to Safe Recipients list</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13359-5' platform='office2010' modified='2013-02-11'>
      <description>The "Hide Junk Mail UI" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Junk E-mail\Hide Junk Mail UI</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13272-0' platform='office2010' modified='2013-02-11'>
      <description>The "Specify path to Blocked Senders list" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Junk E-mail\Specify path to Blocked Senders list</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14877-5' platform='office2010' modified='2013-02-11'>
      <description>The "Specify path to Safe Senders list" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Junk E-mail\Specify path to Safe Senders list</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13462-7' platform='office2010' modified='2013-02-11'>
      <description>The "Add e-mail recipients to users' Safe Senders Lists" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Junk E-mail\Add e-mail recipients to users' Safe Senders Lists</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14452-7' platform='office2010' modified='2013-02-11'>
      <description>The "Junk E-mail protection level" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Junk E-mail\Junk E-mail protection level</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12921-3' platform='office2010' modified='2013-02-11'>
      <description>The "Permanently delete Junk E-mail" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Junk E-mail\Permanently delete Junk E-mail</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14022-8' platform='office2010' modified='2013-02-11'>
      <description>The "Hide warnings about suspicious domain names in e-mail addresses" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Junk E-mail\Hide warnings about suspicious domain names in e-mail addresses</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12912-2' platform='office2010' modified='2013-02-11'>
      <description>The "Trust e-mail from contacts" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Junk E-mail\Trust e-mail from contacts</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13270-4' platform='office2010' modified='2013-02-11'>
      <description>The "Max number of documents being reviewed using 'send for review'" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Collaboration Settings\Max number of documents being reviewed using 'send for review'</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\reviewcycle\docslots</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13445-2' platform='office2010' modified='2013-02-11'>
      <description>The "Outlook: Ad hoc reviewing" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Collaboration Settings\Outlook: Ad hoc reviewing</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14433-7' platform='office2010' modified='2013-02-11'>
      <description>The "Prompt for sending reviewed document to author" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Collaboration Settings\Prompt for sending reviewed document to author</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14302-4' platform='office2010' modified='2013-02-11'>
      <description>The "Default subject for a review request" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Collaboration Settings\Default subject for a review request</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\reviewcycle</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12845-4' platform='office2010' modified='2013-02-11'>
      <description>The "Do not prompt users to share Excel workbooks when sending for review" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Collaboration Settings\Do not prompt users to share Excel workbooks when sending for review</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13829-7' platform='office2010' modified='2013-02-11'>
      <description>The "Max number of documents being reviewed using ad hoc review" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Collaboration Settings\Max number of documents being reviewed using ad hoc review</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\reviewcycle\adhoc\docslots</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14416-2' platform='office2010' modified='2013-02-11'>
      <description>The "Outlook: 'send for review'" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Collaboration Settings\Outlook: 'send for review'</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13796-8' platform='office2010' modified='2013-02-11'>
      <description>The "Hide spelling errors" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath Options\Spelling &amp; Grammar\Hide spelling errors</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\proofing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12747-2' platform='office2010' modified='2013-02-11'>
      <description>The "Default or specific encoding" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Tools | Options | General | Web Options...\Encoding\Default or specific encoding</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13009-6' platform='office2010' modified='2013-02-11'>
      <description>The "Default file format" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Save\Default file format</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14325-5' platform='office2010' modified='2013-02-11'>
      <description>The "Set default compatibility mode on file creation" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Save\Set default compatibility mode on file creation</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12208-5' platform='office2010' modified='2013-02-11'>
      <description>The "Save As Open XML in Compatibility Mode" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Save\Save As Open XML in Compatibility Mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12464-4' platform='office2010' modified='2013-02-11'>
      <description>The "Do not display file format compatibility dialog box for OpenDocument text format" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Save\Do not display file format compatibility dialog box for OpenDocument text format</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12604-5' platform='office2010' modified='2013-02-11'>
      <description>The "Keep the last AutoSaved versions of files for the next session" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Save\Keep the last AutoSaved versions of files for the next session</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13370-2' platform='office2010' modified='2013-02-11'>
      <description>The "Save AutoRecover info" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Save\Save AutoRecover info</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14534-2' platform='office2010' modified='2013-02-11'>
      <description>The "Maximum number of recipients in an Outlook item to scan to determine the user's colleagues for recommendation" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Server Settings\SharePoint Server\Maximum number of recipients in an Outlook item to scan to determine the user's colleagues for recommendation</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\portal\colleagueimport</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14684-5' platform='office2010' modified='2013-02-11'>
      <description>The "Maximum number of items to scan from today to determine the user's colleagues for recommendation" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Server Settings\SharePoint Server\Maximum number of items to scan from today to determine the user's colleagues for recommendation</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\portal\colleagueimport</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13237-3' platform='office2010' modified='2013-02-11'>
      <description>The "Minimum time to wait before rescanning the Outlook mailbox for new colleague recommendations" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Server Settings\SharePoint Server\Minimum time to wait before rescanning the Outlook mailbox for new colleague recommendations</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\portal\colleagueimport</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13020-3' platform='office2010' modified='2013-02-11'>
      <description>The "Enable Colleague Import Outlook Add-in to work with Microsoft SharePoint Server" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Server Settings\SharePoint Server\Enable Colleague Import Outlook Add-in to work with Microsoft SharePoint Server</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\portal\colleagueimport</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13637-4' platform='office2010' modified='2013-02-11'>
      <description>The "Maximum number of days to scan from today to determine the user's colleagues for recommendation" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Server Settings\SharePoint Server\Maximum number of days to scan from today to determine the user's colleagues for recommendation</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\portal\colleagueimport</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12210-1' platform='office2010' modified='2013-02-11'>
      <description>The "Maximum number of rows fetched per request while populating a lookup in the SharePoint list control" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Server Settings\SharePoint Server\Maximum number of rows fetched per request while populating a lookup in the SharePoint list control</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\list\settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12089-9' platform='office2010' modified='2013-02-11'>
      <description>The "Minimum time before starting Colleague recommendation scan" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Server Settings\SharePoint Server\Minimum time before starting Colleague recommendation scan</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\portal\colleagueimport</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12620-1' platform='office2010' modified='2013-02-11'>
      <description>The "Closing style to letter closings" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Proofing\AutoFormat as you type\Apply as you type\Closing style to letter closings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\assist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14276-0' platform='office2010' modified='2013-02-11'>
      <description>The "Tables" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Proofing\AutoFormat as you type\Apply as you type\Tables</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\assist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14841-1' platform='office2010' modified='2013-02-11'>
      <description>The "Border lines" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Proofing\AutoFormat as you type\Apply as you type\Border lines</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\assist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12833-0' platform='office2010' modified='2013-02-11'>
      <description>The "Automatic numbered lists" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Proofing\AutoFormat as you type\Apply as you type\Automatic numbered lists</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\assist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14430-3' platform='office2010' modified='2013-02-11'>
      <description>The "Date style" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Proofing\AutoFormat as you type\Apply as you type\Date style</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\assist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13483-3' platform='office2010' modified='2013-02-11'>
      <description>The "Automatic bulleted lists" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Proofing\AutoFormat as you type\Apply as you type\Automatic bulleted lists</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\assist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13510-3' platform='office2010' modified='2013-02-11'>
      <description>The "Headings" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Proofing\AutoFormat as you type\Apply as you type\Headings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\assist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13159-9' platform='office2010' modified='2013-02-11'>
      <description>The "Default end time" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calendar\Default end time</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14201-8' platform='office2010' modified='2013-02-11'>
      <description>The "Default start time" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calendar\Default start time</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12021-2' platform='office2010' modified='2013-02-11'>
      <description>The "Days per month" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calendar\Days per month</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14489-9' platform='office2010' modified='2013-02-11'>
      <description>The "Week starts on" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calendar\Week starts on</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13187-0' platform='office2010' modified='2013-02-11'>
      <description>The "Fiscal year starts in" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calendar\Fiscal year starts in</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12462-8' platform='office2010' modified='2013-02-11'>
      <description>The "Hours per day" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calendar\Hours per day</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13284-5' platform='office2010' modified='2013-02-11'>
      <description>The "Hours per week" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calendar\Hours per week</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12835-5' platform='office2010' modified='2013-02-11'>
      <description>The "Use starting year for FY numbering" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calendar\Use starting year for FY numbering</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12696-1' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Data Execution Prevention" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Security\Trust Center\Turn off Data Execution Prevention</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12676-3' platform='office2010' modified='2013-02-11'>
      <description>The "Set document synchronization timeout" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Collaboration Settings\Co-authoring\Set document synchronization timeout</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13612-7' platform='office2010' modified='2013-02-11'>
      <description>The "Disable commands" SharePoint Designer setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft SharePoint Designer 2010\Disable Items in User Interface\Custom\Disable commands</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\sharepoint designer\disabledcmdbaritemslist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13649-9' platform='office2010' modified='2013-02-11'>
      <description>The "Baseline for Earned Value calculations" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calculation\Calculation options for 'Project1'\Earned Value options for Project1\Baseline for Earned Value calculations</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calculation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12398-4' platform='office2010' modified='2013-02-11'>
      <description>The "Default task Earned Value method" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calculation\Calculation options for 'Project1'\Earned Value options for Project1\Default task Earned Value method</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calculation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12829-8' platform='office2010' modified='2013-02-11'>
      <description>The "Rewind from start of paragraph by the following number of seconds" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Audio and Video\Rewind from start of paragraph by the following number of seconds</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\audio</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12000-6' platform='office2010' modified='2013-02-11'>
      <description>The "Specify number of channels to record" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Audio and Video\Specify number of channels to record</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\audio</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12229-1' platform='office2010' modified='2013-02-11'>
      <description>The "Choose default codec to be used for Video notebook" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Audio and Video\Choose default codec to be used for Video notebook</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\audio</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13897-4' platform='office2010' modified='2013-02-11'>
      <description>The "Disable audio search" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Audio and Video\Disable audio search</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\other</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13739-8' platform='office2010' modified='2013-02-11'>
      <description>The "Specify rate to sample audio (bits/second)" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Audio and Video\Specify rate to sample audio (bits/second)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\audio</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13044-3' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Linked Audio feature" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Audio and Video\Disable Linked Audio feature</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\audio</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13455-1' platform='office2010' modified='2013-02-11'>
      <description>The "Specify number of bits to sample when recording" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Audio and Video\Specify number of bits to sample when recording</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\audio</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13153-2' platform='office2010' modified='2013-02-11'>
      <description>The "Turn on purge when switching folders" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\IMAP\Turn on purge when switching folders</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12539-3' platform='office2010' modified='2013-02-11'>
      <description>The "Set signature verification level" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Set signature verification level</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\signatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14040-0' platform='office2010' modified='2013-02-11'>
      <description>The "Disable All ActiveX" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Disable All ActiveX</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14352-9' platform='office2010' modified='2013-02-11'>
      <description>The "Do not include XAdES reference object in the manifest" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Do not include XAdES reference object in the manifest</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\signatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14166-3' platform='office2010' modified='2013-02-11'>
      <description>The "Configure time stamping hashing algorithm" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Configure time stamping hashing algorithm</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\signatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12299-4' platform='office2010' modified='2013-02-11'>
      <description>The "Select digital signature hashing algorithm" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Select digital signature hashing algorithm</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\signatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12689-6' platform='office2010' modified='2013-02-11'>
      <description>The "ActiveX Control Initialization" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\ActiveX Control Initialization</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11982-6' platform='office2010' modified='2013-02-11'>
      <description>The "Encryption type for password protected Office Open XML files" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Encryption type for password protected Office Open XML files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13998-0' platform='office2010' modified='2013-02-11'>
      <description>The "Protect document metadata for rights managed Office Open XML Files" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Protect document metadata for rights managed Office Open XML Files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13273-8' platform='office2010' modified='2013-02-11'>
      <description>The "Check the XAdES portions of a digital signature" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Check the XAdES portions of a digital signature</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\signatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13658-0' platform='office2010' modified='2013-02-11'>
      <description>The "Disable password to open UI" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Disable password to open UI</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13597-0' platform='office2010' modified='2013-02-11'>
      <description>The "Require OCSP at signature generation time" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Require OCSP at signature generation time</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\signatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13878-4' platform='office2010' modified='2013-02-11'>
      <description>The "Set timestamp server timeout" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Set timestamp server timeout</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\signatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13734-9' platform='office2010' modified='2013-02-11'>
      <description>The "Set minimum password length" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Set minimum password length</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\passwordcomplexity</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13204-3' platform='office2010' modified='2013-02-11'>
      <description>The "Protect document metadata for password protected files" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Protect document metadata for password protected files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12185-5' platform='office2010' modified='2013-02-11'>
      <description>The "Check Excel RTD servers" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Check Excel RTD servers</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\com categories</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13591-3' platform='office2010' modified='2013-02-11'>
      <description>The "Check OWC data source providers" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Check OWC data source providers</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\com categories</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13844-6' platform='office2010' modified='2013-02-11'>
      <description>The "Requested XAdES level for signature generation" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Requested XAdES level for signature generation</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\signatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14045-9' platform='office2010' modified='2013-02-11'>
      <description>The "Set password hash format as ISO-compliant" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Set password hash format as ISO-compliant</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14658-9' platform='office2010' modified='2013-02-11'>
      <description>The "Automation Security" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Automation Security</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14561-5' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent Word and Excel from loading managed code extensions" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Prevent Word and Excel from loading managed code extensions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\smart tag</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14471-7' platform='office2010' modified='2013-02-11'>
      <description>The "Set password rules domain timeout" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Set password rules domain timeout</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\passwordcomplexity</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13353-8' platform='office2010' modified='2013-02-11'>
      <description>The "Disable all Trust Bar notifications for security issues" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Disable all Trust Bar notifications for security issues</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\trustcenter</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11675-6' platform='office2010' modified='2013-02-11'>
      <description>The "Disable VBA for Office applications" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Disable VBA for Office applications</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11532-9' platform='office2010' modified='2013-02-11'>
      <description>The "Encrypt document properties" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Encrypt document properties</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14173-9' platform='office2010' modified='2013-02-11'>
      <description>The "Set password rules level" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Set password rules level</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\passwordcomplexity</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12146-7' platform='office2010' modified='2013-02-11'>
      <description>The "Load Controls in Forms3" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Load Controls in Forms3</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\vba\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13030-2' platform='office2010' modified='2013-02-11'>
      <description>The "Encryption type for password protected Office 97-2003 files" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Encryption type for password protected Office 97-2003 files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12055-0' platform='office2010' modified='2013-02-11'>
      <description>The "Check ActiveX objects" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Check ActiveX objects</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\com categories</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13656-4' platform='office2010' modified='2013-02-11'>
      <description>The "Check OLE objects" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Check OLE objects</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\com categories</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14199-4' platform='office2010' modified='2013-02-11'>
      <description>The "Do not allow expired certificates when validating signatures" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Do not allow expired certificates when validating signatures</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\signatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14476-6' platform='office2010' modified='2013-02-11'>
      <description>The "Use Protected View for attachments received from internal senders" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Use Protected View for attachments received from internal senders</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14866-8' platform='office2010' modified='2013-02-11'>
      <description>The "Prompt user to choose security settings if default settings fail" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Prompt user to choose security settings if default settings fail</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12816-5' platform='office2010' modified='2013-02-11'>
      <description>The "Configure Add-In Trust Level" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Configure Add-In Trust Level</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13784-4' platform='office2010' modified='2013-02-11'>
      <description>The "Allow Active X One Off Forms" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Allow Active X One Off Forms</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14219-0' platform='office2010' modified='2013-02-11'>
      <description>The "Do not automatically sign replies" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Do not automatically sign replies</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12618-5' platform='office2010' modified='2013-02-11'>
      <description>The "Disable 'Remember password' for Internet e-mail accounts" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Disable 'Remember password' for Internet e-mail accounts</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12962-7' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent users from customizing attachment security settings" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Prevent users from customizing attachment security settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12444-6' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Trust Bar Notification for unsigned application add-ins and block them" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Disable Trust Bar Notification for unsigned application add-ins and block them</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12651-6' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #14" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Trusted Location #14</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations\location14</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12616-9' platform='office2010' modified='2013-02-11'>
      <description>The "Allow Trusted Locations on the network" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Allow Trusted Locations on the network</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13409-8' platform='office2010' modified='2013-02-11'>
      <description>The "Set maximum number of trust records to preserve" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Set maximum number of trust records to preserve</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted documents</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14637-3' platform='office2010' modified='2013-02-11'>
      <description>The "Disable all application add-ins" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Disable all application add-ins</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13145-8' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #17" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Trusted Location #17</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations\location17</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13496-5' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #4" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Trusted Location #4</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations\location4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13468-4' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #13" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Trusted Location #13</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations\location13</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12052-7' platform='office2010' modified='2013-02-11'>
      <description>The "VBA Macro Notification Settings" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\VBA Macro Notification Settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13479-1' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #15" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Trusted Location #15</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations\location15</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11868-7' platform='office2010' modified='2013-02-11'>
      <description>The "Set maximum number of trusted documents" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Set maximum number of trusted documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted documents</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12533-6' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #9" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Trusted Location #9</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations\location9</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12380-2' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #10" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Trusted Location #10</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations\location10</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13896-6' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #11" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Trusted Location #11</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations\location11</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13665-5' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #19" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Trusted Location #19</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations\location19</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13403-1' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #18" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Trusted Location #18</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations\location18</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12122-8' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #6" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Trusted Location #6</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations\location6</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12526-0' platform='office2010' modified='2013-02-11'>
      <description>The "Disable all trusted locations" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Disable all trusted locations</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13010-4' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #1" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Trusted Location #1</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations\location1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13390-0' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #3" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Trusted Location #3</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations\location3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13988-1' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #5" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Trusted Location #5</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations\location5</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12218-4' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off trusted documents" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Turn off trusted documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted documents</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12297-8' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #16" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Trusted Location #16</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations\location16</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13055-9' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Trusted Documents on the network" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Turn off Trusted Documents on the network</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted documents</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14886-6' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #12" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Trusted Location #12</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations\location12</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11790-3' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #7" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Trusted Location #7</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations\location7</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12358-8' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Data Execution Prevention" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Turn off Data Execution Prevention</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13414-8' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #8" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Trusted Location #8</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations\location8</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12558-3' platform='office2010' modified='2013-02-11'>
      <description>The "Require that application add-ins are signed by Trusted Publisher" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Require that application add-ins are signed by Trusted Publisher</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14178-8' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #20" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Trusted Location #20</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations\location20</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13791-9' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #2" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Trust Center\Trusted Location #2</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\security\trusted locations\location2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13206-8' platform='office2010' modified='2013-02-11'>
      <description>The "Load Microsoft Visual Basic for Applications projects from text" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Macro Security\Load Microsoft Visual Basic for Applications projects from text</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12432-1' platform='office2010' modified='2013-02-11'>
      <description>The "Enable Microsoft Visual Basic for Applications project creation" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Security\Macro Security\Enable Microsoft Visual Basic for Applications project creation</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14473-3' platform='office2010' modified='2013-02-11'>
      <description>The "Do not show Mini Toolbar on selection of text" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\General\User Interface Options\Do not show Mini Toolbar on selection of text</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13659-8' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Live Preview in the Shapes window" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\General\User Interface Options\Turn off Live Preview in the Shapes window</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13876-8' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Live Preview" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\General\User Interface Options\Turn off Live Preview</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14123-4' platform='office2010' modified='2013-02-11'>
      <description>The "Number of backup copies to keep" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Backup\Number of backup copies to keep</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\save</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14485-7' platform='office2010' modified='2013-02-11'>
      <description>The "Automatically back up my notebook..." OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Backup\Automatically back up my notebook...</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\save</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14624-1' platform='office2010' modified='2013-02-11'>
      <description>The "Move start of remaining parts before status date forward to status date" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calculation\Calculation options for 'Project1'\Move start of remaining parts before status date forward to status date</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calculation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11952-9' platform='office2010' modified='2013-02-11'>
      <description>The "Edits to total actual cost will be spread to the status date" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calculation\Calculation options for 'Project1'\Edits to total actual cost will be spread to the status date</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calculation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13474-2' platform='office2010' modified='2013-02-11'>
      <description>The "And move end of completed parts forward to status date" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calculation\Calculation options for 'Project1'\And move end of completed parts forward to status date</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calculation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13780-2' platform='office2010' modified='2013-02-11'>
      <description>The "Default fixed costs accrual" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calculation\Calculation options for 'Project1'\Default fixed costs accrual</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calculation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13765-3' platform='office2010' modified='2013-02-11'>
      <description>The "Calculate multiple critical paths" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calculation\Calculation options for 'Project1'\Calculate multiple critical paths</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calculation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14184-6' platform='office2010' modified='2013-02-11'>
      <description>The "Edits to total task % complete will be spread to the status date" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calculation\Calculation options for 'Project1'\Edits to total task % complete will be spread to the status date</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calculation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13146-6' platform='office2010' modified='2013-02-11'>
      <description>The "Move end of completed parts after status date back to status date" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calculation\Calculation options for 'Project1'\Move end of completed parts after status date back to status date</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calculation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12184-8' platform='office2010' modified='2013-02-11'>
      <description>The "Tasks are critical if slack is less than or equal to" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calculation\Calculation options for 'Project1'\Tasks are critical if slack is less than or equal to</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calculation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12530-2' platform='office2010' modified='2013-02-11'>
      <description>The "Updating task status updates resource status" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calculation\Calculation options for 'Project1'\Updating task status updates resource status</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calculation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12452-9' platform='office2010' modified='2013-02-11'>
      <description>The "And move start of remaining parts back to status date" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calculation\Calculation options for 'Project1'\And move start of remaining parts back to status date</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calculation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13267-0' platform='office2010' modified='2013-02-11'>
      <description>The "Actual costs are always calculated by Microsoft Project" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calculation\Calculation options for 'Project1'\Actual costs are always calculated by Microsoft Project</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calculation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11826-5' platform='office2010' modified='2013-02-11'>
      <description>The "Inserted projects are calculated like summary tasks" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Calculation\Calculation options for 'Project1'\Inserted projects are calculated like summary tasks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\calculation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13097-1' platform='office2010' modified='2013-02-11'>
      <description>The "Previous-version file formats" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Security\Previous-version file formats</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11859-6' platform='office2010' modified='2013-02-11'>
      <description>The "Ink Entry" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath Options\Ink\Ink Entry</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\editorcommon</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11562-6' platform='office2010' modified='2013-02-11'>
      <description>The "Display a shaded ink guide for handwriting" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath Options\Ink\Display a shaded ink guide for handwriting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\editorcommon</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12853-8' platform='office2010' modified='2013-02-11'>
      <description>The "Display a warning dialog box that user is entering text in Ink entry mode" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath Options\Ink\Display a warning dialog box that user is entering text in Ink entry mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\editorcommon</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13827-1' platform='office2010' modified='2013-02-11'>
      <description>The "Enter milliseconds before recognizing handwriting" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath Options\Ink\Enter milliseconds before recognizing handwriting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\editorcommon</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14348-7' platform='office2010' modified='2013-02-11'>
      <description>The "Display Developer tab in the Ribbon" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Customize Ribbon\Display Developer tab in the Ribbon</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13557-4' platform='office2010' modified='2013-02-11'>
      <description>The "Do not automatically merge server and local document" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Collaboration Settings\Co-authoring\Do not automatically merge server and local document</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\coauthoring</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12233-3' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent co-authoring" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Collaboration Settings\Co-authoring\Prevent co-authoring</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\coauthoring</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13513-7' platform='office2010' modified='2013-02-11'>
      <description>The "Match hyu/iyu, byu/vyu" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Japanese Find\Match hyu/iyu, byu/vyu</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpreffuz</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13265-4' platform='office2010' modified='2013-02-11'>
      <description>The "Match 'repeat character' marks" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Japanese Find\Match 'repeat character' marks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpreffuz</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11607-9' platform='office2010' modified='2013-02-11'>
      <description>The "Match ki/ku (tekisuto/tekusuto)" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Japanese Find\Match ki/ku (tekisuto/tekusuto)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpreffuz</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13718-2' platform='office2010' modified='2013-02-11'>
      <description>The "Match full/half width form" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Japanese Find\Match full/half width form</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpreffuz</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13699-4' platform='office2010' modified='2013-02-11'>
      <description>The "Ignore whitespace characters" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Japanese Find\Ignore whitespace characters</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpreffuz</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12304-2' platform='office2010' modified='2013-02-11'>
      <description>The "Match cho-on used for vowels" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Japanese Find\Match cho-on used for vowels</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpreffuz</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12997-3' platform='office2010' modified='2013-02-11'>
      <description>The "Match tsi/thi/chi, dhi/zi" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Japanese Find\Match tsi/thi/chi, dhi/zi</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpreffuz</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13354-6' platform='office2010' modified='2013-02-11'>
      <description>The "Match se/she, ze/je" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Japanese Find\Match se/she, ze/je</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpreffuz</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12330-7' platform='office2010' modified='2013-02-11'>
      <description>The "Match ba/va, ha/fa" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Japanese Find\Match ba/va, ha/fa</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpreffuz</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13800-8' platform='office2010' modified='2013-02-11'>
      <description>The "Match variant-form kanji (itaiji)" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Japanese Find\Match variant-form kanji (itaiji)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpreffuz</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14697-7' platform='office2010' modified='2013-02-11'>
      <description>The "Ignore punctuation characters" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Japanese Find\Ignore punctuation characters</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpreffuz</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13766-1' platform='office2010' modified='2013-02-11'>
      <description>The "Match old kana forms" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Japanese Find\Match old kana forms</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpreffuz</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14070-7' platform='office2010' modified='2013-02-11'>
      <description>The "Match contractions (yo-on, sokuon)" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Japanese Find\Match contractions (yo-on, sokuon)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpreffuz</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12333-1' platform='office2010' modified='2013-02-11'>
      <description>The "Match di/zi, du/zu" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Japanese Find\Match di/zi, du/zu</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpreffuz</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13421-3' platform='office2010' modified='2013-02-11'>
      <description>The "Match case" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Japanese Find\Match case</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpreffuz</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12887-6' platform='office2010' modified='2013-02-11'>
      <description>The "Match ia/iya (piano/piyano)" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Japanese Find\Match ia/iya (piano/piyano)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpreffuz</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12313-3' platform='office2010' modified='2013-02-11'>
      <description>The "Match hiragana/katakana" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Japanese Find\Match hiragana/katakana</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpreffuz</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12315-8' platform='office2010' modified='2013-02-11'>
      <description>The "Match minus/dash/cho-on" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Japanese Find\Match minus/dash/cho-on</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpreffuz</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14520-1' platform='office2010' modified='2013-02-11'>
      <description>The "Display Developer tab in the Ribbon" Publisher setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Publisher 2010\Publisher Options\Customize Ribbon\Display Developer tab in the Ribbon</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\publisher\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13969-1' platform='office2010' modified='2013-02-11'>
      <description>The "Default database folder" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\General\Default database folder</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12440-4' platform='office2010' modified='2013-02-11'>
      <description>The "Number of documents in the Recent Documents list" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\General\Number of documents in the Recent Documents list</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12745-6' platform='office2010' modified='2013-02-11'>
      <description>The "Automatically download attachments" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Internet Calendars\Automatically download attachments</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\webcal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12902-3' platform='office2010' modified='2013-02-11'>
      <description>The "Override published sync interval" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Internet Calendars\Override published sync interval</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\webcal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14207-5' platform='office2010' modified='2013-02-11'>
      <description>The "Default Internet Calendar subscriptions" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Internet Calendars\Default Internet Calendar subscriptions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\accounts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13632-5' platform='office2010' modified='2013-02-11'>
      <description>The "Disable roaming of Internet Calendars" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Internet Calendars\Disable roaming of Internet Calendars</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\webcal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14936-9' platform='office2010' modified='2013-02-11'>
      <description>The "Do not include Internet Calendar integration in Outlook" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Internet Calendars\Do not include Internet Calendar integration in Outlook</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\webcal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13577-2' platform='office2010' modified='2013-02-11'>
      <description>The "Calendar Type" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\View\Calendar Type\Calendar Type</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\view</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12825-6' platform='office2010' modified='2013-02-11'>
      <description>The "Path to shared Workgroup information file for secured MDB files" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Tools | Security\Workgroup Administrator...\Path to shared Workgroup information file for secured MDB files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\access connectivity engine\engines</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11815-8' platform='office2010' modified='2013-02-11'>
      <description>The "Display Developer tab in the Ribbon" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Customize Ribbon\Display Developer tab in the Ribbon</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12925-4' platform='office2010' modified='2013-02-11'>
      <description>The "Disable OneNote COM API" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Add-ins\Disable OneNote COM API</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13914-7' platform='office2010' modified='2013-02-11'>
      <description>The "Disable installed OneNote Add-ins" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Add-ins\Disable installed OneNote Add-ins</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14376-8' platform='office2010' modified='2013-02-11'>
      <description>The "Default direction" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\International\Default direction</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13393-4' platform='office2010' modified='2013-02-11'>
      <description>The "Cursor movement" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\International\Cursor movement</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12417-2' platform='office2010' modified='2013-02-11'>
      <description>The "General Alignment" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\International\General Alignment</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\settings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12654-0' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking for table header accessibility information" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\File Tab\Check Accessibility\Stop checking for table header accessibility information</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14823-9' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking for blank table rows and columns" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\File Tab\Check Accessibility\Stop checking for blank table rows and columns</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13465-0' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking to ensure each slide has a unique title" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\File Tab\Check Accessibility\Stop checking to ensure each slide has a unique title</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13180-5' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking for merged and split cells" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\File Tab\Check Accessibility\Stop checking for merged and split cells</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12286-1' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking for alt text accessibility information" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\File Tab\Check Accessibility\Stop checking for alt text accessibility information</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14903-9' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking to ensure hyperlink text is meaningful" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\File Tab\Check Accessibility\Stop checking to ensure hyperlink text is meaningful</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14428-7' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking to ensure a meaningful order of objects on slides" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\File Tab\Check Accessibility\Stop checking to ensure a meaningful order of objects on slides</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13570-7' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking for media files which might need captions" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\File Tab\Check Accessibility\Stop checking for media files which might need captions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12984-1' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking to ensure presentations allow programmatic access" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\File Tab\Check Accessibility\Stop checking to ensure presentations allow programmatic access</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14349-5' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking that slide titles exist" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\File Tab\Check Accessibility\Stop checking that slide titles exist</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12446-1' platform='office2010' modified='2013-02-11'>
      <description>The "Publisher Automation Security Level" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Publisher 2010\Security\Publisher Automation Security Level</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12353-9' platform='office2010' modified='2013-02-11'>
      <description>The "Prompt to allow fatally corrupt files to open instead of blocking them" Publisher setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Publisher 2010\Security\Prompt to allow fatally corrupt files to open instead of blocking them</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\publisher</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13327-2' platform='office2010' modified='2013-02-11'>
      <description>The "Do not show ScreenTips on toolbars" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Global Options\Customize\Do not show ScreenTips on toolbars</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12212-7' platform='office2010' modified='2013-02-11'>
      <description>The "Menu animations" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Global Options\Customize\Menu animations</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12477-6' platform='office2010' modified='2013-02-11'>
      <description>The "List font names in their font" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Global Options\Customize\List font names in their font</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13908-9' platform='office2010' modified='2013-02-11'>
      <description>The "Disable UI extending from documents and templates" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Global Options\Customize\Disable UI extending from documents and templates</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\toolbars\publisher</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14252-1' platform='office2010' modified='2013-02-11'>
      <description>The "Allow roaming of all user customizations" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Global Options\Customize\Allow roaming of all user customizations</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13646-5' platform='office2010' modified='2013-02-11'>
      <description>The "Show shortcut keys in ScreenTips" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Global Options\Customize\Show shortcut keys in ScreenTips</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14370-1' platform='office2010' modified='2013-02-11'>
      <description>The "Large icons" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Global Options\Customize\Large icons</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13361-1' platform='office2010' modified='2013-02-11'>
      <description>The "Resource Assigments" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Interface\Show indicators and Option butons for\Resource Assigments</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\interface</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14651-4' platform='office2010' modified='2013-02-11'>
      <description>The "Edits to work, units or duration" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Interface\Show indicators and Option butons for\Edits to work, units or duration</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\interface</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13754-7' platform='office2010' modified='2013-02-11'>
      <description>The "Edits to start and finish dates" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Interface\Show indicators and Option butons for\Edits to start and finish dates</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\interface</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13116-9' platform='office2010' modified='2013-02-11'>
      <description>The "Deletions in the Name column" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Interface\Show indicators and Option butons for\Deletions in the Name column</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\interface</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13675-4' platform='office2010' modified='2013-02-11'>
      <description>The "Disable commands" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Disable Items in User Interface\Custom\Disable commands</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\disabledcmdbaritemslist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14556-5' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent Token Activation dialog from closing" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft Office 2010 (Machine)\Volume Activation\Prevent Token Activation dialog from closing</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\officesoftwareprotectionplatform</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12252-3' platform='office2010' modified='2013-02-11'>
      <description>The "Use only Token Activation" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft Office 2010 (Machine)\Volume Activation\Use only Token Activation</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\officesoftwareprotectionplatform</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13837-0' platform='office2010' modified='2013-02-11'>
      <description>The "Use contextual spelling" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Proofing\Use contextual spelling</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\shared tools\proofing tools\1.0\office</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13886-7' platform='office2010' modified='2013-02-11'>
      <description>The "Check spelling as you type" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Proofing\Check spelling as you type</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13364-5' platform='office2010' modified='2013-02-11'>
      <description>The "Enable Automation events" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\General Options\Enable Automation events</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13716-6' platform='office2010' modified='2013-02-11'>
      <description>The "Put all settings in Windows registry" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\General Options\Put all settings in Windows registry</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14504-5' platform='office2010' modified='2013-02-11'>
      <description>The "Open each ShapeSheet in the same window" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\General Options\Open each ShapeSheet in the same window</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\document</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12688-8' platform='office2010' modified='2013-02-11'>
      <description>The "Language for file conversion" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Save/Open\Language for file conversion</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13630-9' platform='office2010' modified='2013-02-11'>
      <description>The "Show file open warnings" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Save/Open\Show file open warnings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12632-6' platform='office2010' modified='2013-02-11'>
      <description>The "Show file save warnings" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Save/Open\Show file save warnings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14064-0' platform='office2010' modified='2013-02-11'>
      <description>The "Do not show social network info-bars" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Social Connector\Do not show social network info-bars</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\outlook\socialconnector</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13975-8' platform='office2010' modified='2013-02-11'>
      <description>The "Block network activity synchronization" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Social Connector\Block network activity synchronization</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\outlook\socialconnector</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11820-8' platform='office2010' modified='2013-02-11'>
      <description>The "Set GAL contact synchronization interval" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Social Connector\Set GAL contact synchronization interval</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\outlook\socialconnector</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12664-9' platform='office2010' modified='2013-02-11'>
      <description>The "Do not download photos from Active Directory" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Social Connector\Do not download photos from Active Directory</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\outlook\socialconnector</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11989-1' platform='office2010' modified='2013-02-11'>
      <description>The "Do not allow on-demand activity synchronization" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Social Connector\Do not allow on-demand activity synchronization</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\outlook\socialconnector</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14899-9' platform='office2010' modified='2013-02-11'>
      <description>The "Block specific social network providers" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Social Connector\Block specific social network providers</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\outlook\socialconnector</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14304-0' platform='office2010' modified='2013-02-11'>
      <description>The "Specify activity feed synchronization interval" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Social Connector\Specify activity feed synchronization interval</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\outlook\socialconnector</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14775-1' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent social network connectivity" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Social Connector\Prevent social network connectivity</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\outlook\socialconnector</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13834-7' platform='office2010' modified='2013-02-11'>
      <description>The "Block social network contact synchronization" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Social Connector\Block social network contact synchronization</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\outlook\socialconnector</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13347-0' platform='office2010' modified='2013-02-11'>
      <description>The "Specify list of social network providers to load" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Social Connector\Specify list of social network providers to load</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\outlook\socialconnector</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14043-4' platform='office2010' modified='2013-02-11'>
      <description>The "Block Global Address List synchronization" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Social Connector\Block Global Address List synchronization</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\outlook\socialconnector</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12959-3' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Outlook Social Connector" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Social Connector\Turn off Outlook Social Connector</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\outlook\socialconnector</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13538-4' platform='office2010' modified='2013-02-11'>
      <description>The "List of error messages to customize" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Customizable Error Messages\List of error messages to customize</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\customizablealerts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13851-1' platform='office2010' modified='2013-02-11'>
      <description>The "Insert closing phrase to match Japanese salutation" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Proofing\AutoFormat as you type\Automatically as you type\Insert closing phrase to match Japanese salutation</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\assist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13512-9' platform='office2010' modified='2013-02-11'>
      <description>The "Auto space" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Proofing\AutoFormat as you type\Automatically as you type\Auto space</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\assist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13487-4' platform='office2010' modified='2013-02-11'>
      <description>The "Insert closing phrase to match memo style" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Proofing\AutoFormat as you type\Automatically as you type\Insert closing phrase to match memo style</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\assist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13031-0' platform='office2010' modified='2013-02-11'>
      <description>The "Set left indent on tabs and backspace" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Proofing\AutoFormat as you type\Automatically as you type\Set left indent on tabs and backspace</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\assist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12790-2' platform='office2010' modified='2013-02-11'>
      <description>The "Define styles based on your formatting" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Proofing\AutoFormat as you type\Automatically as you type\Define styles based on your formatting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\assist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14693-6' platform='office2010' modified='2013-02-11'>
      <description>The "Format beginning of list item like the one before it" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Proofing\AutoFormat as you type\Automatically as you type\Format beginning of list item like the one before it</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\assist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12939-5' platform='office2010' modified='2013-02-11'>
      <description>The "Match parentheses" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Proofing\AutoFormat as you type\Automatically as you type\Match parentheses</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\assist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13046-8' platform='office2010' modified='2013-02-11'>
      <description>The "Display Developer tab in the Ribbon" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Customize Ribbon\Display Developer tab in the Ribbon</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12026-1' platform='office2010' modified='2013-02-11'>
      <description>The "Disable task list" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Task Options\Disable task list</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\todobar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12500-5' platform='office2010' modified='2013-02-11'>
      <description>The "Do not display the To-Do Bar" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Task Options\Do not display the To-Do Bar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\todobar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12448-7' platform='office2010' modified='2013-02-11'>
      <description>The "To-Do Bar Date Navigators" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Task Options\To-Do Bar Date Navigators</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\todobar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14379-2' platform='office2010' modified='2013-02-11'>
      <description>The "Do not display Quick Contacts in the To-Do Bar" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Task Options\Do not display Quick Contacts in the To-Do Bar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\todobar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13622-6' platform='office2010' modified='2013-02-11'>
      <description>The "Disable shortcut keys" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Disable Items in User Interface\Custom\Disable shortcut keys</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\disabledshortcutkeyslist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14145-7' platform='office2010' modified='2013-02-11'>
      <description>The "Disable commands" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Disable Items in User Interface\Custom\Disable commands</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\disabledcmdbaritemslist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13108-6' platform='office2010' modified='2013-02-11'>
      <description>The "Disable features not supported by specified browsers" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Web Options...\Browser\Disable features not supported by specified browsers</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13218-3' platform='office2010' modified='2013-02-11'>
      <description>The "Groove Server Manager Name" SharePoint Workspace setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft SharePoint Workspace 2010\Groove Server Manager\Groove Server Manager Name</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\groove\manager</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14596-1' platform='office2010' modified='2013-02-11'>
      <description>The "Outlook Today availability" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Today Settings\Outlook Today availability</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\today</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14028-5' platform='office2010' modified='2013-02-11'>
      <description>The "URL for custom Outlook Today" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Today Settings\URL for custom Outlook Today</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\today</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13563-2' platform='office2010' modified='2013-02-11'>
      <description>The "Specify delay before sending people search request" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Miscellaneous\Specify delay before sending people search request</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\im</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11937-0' platform='office2010' modified='2013-02-11'>
      <description>The "Do not show unread message count on Windows Welcome screen" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Miscellaneous\Do not show unread message count on Windows Welcome screen</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12529-4' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent users from making changes to Outlook profiles" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Miscellaneous\Prevent users from making changes to Outlook profiles</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\setup</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13920-4' platform='office2010' modified='2013-02-11'>
      <description>The "Do not expand Contact Groups" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Miscellaneous\Do not expand Contact Groups</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14890-8' platform='office2010' modified='2013-02-11'>
      <description>The "Only show Auto Account Setup on first boot" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Miscellaneous\Only show Auto Account Setup on first boot</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12480-0' platform='office2010' modified='2013-02-11'>
      <description>The "Automatically show the Outlook Attachment pane when adding attachment" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Miscellaneous\Automatically show the Outlook Attachment pane when adding attachment</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\mailsettings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12741-5' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off fast people search" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Miscellaneous\Turn off fast people search</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\im</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12160-8' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off SharePoint Portal Server Colleague Import" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Miscellaneous\Turn off SharePoint Portal Server Colleague Import</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\portal\colleagueimport</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14197-8' platform='office2010' modified='2013-02-11'>
      <description>The "Add new categories" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Miscellaneous\Add new categories</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14165-5' platform='office2010' modified='2013-02-11'>
      <description>The "Do not display "Open this task" button for workflow tasks" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Miscellaneous\Do not display "Open this task" button for workflow tasks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\workflow</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13683-8' platform='office2010' modified='2013-02-11'>
      <description>The "Extend Outlook Autosave to include encrypted e-mail messages" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Miscellaneous\Extend Outlook Autosave to include encrypted e-mail messages</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\mailsettings</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12555-9' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent users from adding e-mail account types" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Miscellaneous\Prevent users from adding e-mail account types</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14114-3' platform='office2010' modified='2013-02-11'>
      <description>The "Disable VLV Browsing on LDAP servers" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Miscellaneous\Disable VLV Browsing on LDAP servers</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\ldap</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12071-7' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Windows event logging for Outlook add-ins" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Miscellaneous\Disable Windows event logging for Outlook add-ins</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\logging</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13655-6' platform='office2010' modified='2013-02-11'>
      <description>The "PAB Migration" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Miscellaneous\PAB Migration</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\setup</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12702-7' platform='office2010' modified='2013-02-11'>
      <description>The "Do not download rights permission license information for IRM e-mail during Exchange folder sync" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Miscellaneous\Do not download rights permission license information for IRM e-mail during Exchange folder sync</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\drm</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12151-7' platform='office2010' modified='2013-02-11'>
      <description>The "Managing Categories during e-mail exchanges" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Miscellaneous\Managing Categories during e-mail exchanges</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12428-9' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent MAPI services from being added" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Miscellaneous\Prevent MAPI services from being added</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14484-0' platform='office2010' modified='2013-02-11'>
      <description>The "Default Doctype" SharePoint Designer setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft SharePoint Designer 2010\Default Authoring Options\Default Doctype</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\sharepoint designer\restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11915-6' platform='office2010' modified='2013-02-11'>
      <description>The "Default New Page Type on SharePoint" SharePoint Designer setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft SharePoint Designer 2010\Default Authoring Options\Default New Page Type on SharePoint</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\sharepoint designer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14521-9' platform='office2010' modified='2013-02-11'>
      <description>The "Default CSS Schema" SharePoint Designer setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft SharePoint Designer 2010\Default Authoring Options\Default CSS Schema</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\sharepoint designer\restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12415-6' platform='office2010' modified='2013-02-11'>
      <description>The "Default New Page Type" SharePoint Designer setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft SharePoint Designer 2010\Default Authoring Options\Default New Page Type</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\sharepoint designer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12543-5' platform='office2010' modified='2013-02-11'>
      <description>The "Default Secondary Schema" SharePoint Designer setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft SharePoint Designer 2010\Default Authoring Options\Default Secondary Schema</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\sharepoint designer\restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13249-8' platform='office2010' modified='2013-02-11'>
      <description>The "Allow attendees to propose new times for meetings you organize" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Allow attendees to propose new times for meetings you organize</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12569-0' platform='office2010' modified='2013-02-11'>
      <description>The "Hide lucky days when using Rokuyou (Japanese) calendar" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Hide lucky days when using Rokuyou (Japanese) calendar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14024-4' platform='office2010' modified='2013-02-11'>
      <description>The "Do not regenerate meetings" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Do not regenerate meetings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14408-9' platform='office2010' modified='2013-02-11'>
      <description>The "Show details of private appointments" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Show details of private appointments</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\todobar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13938-6' platform='office2010' modified='2013-02-11'>
      <description>The "Send Internet meeting requests using iCalendar format" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Send Internet meeting requests using iCalendar format</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12524-5' platform='office2010' modified='2013-02-11'>
      <description>The "Do not display reminders on Calendar items by default" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Do not display reminders on Calendar items by default</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14152-3' platform='office2010' modified='2013-02-11'>
      <description>The "Secondary calendar settings" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Secondary calendar settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13915-4' platform='office2010' modified='2013-02-11'>
      <description>The "Calendar item defaults" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Calendar item defaults</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13124-3' platform='office2010' modified='2013-02-11'>
      <description>The "Working hours" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Working hours</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12392-7' platform='office2010' modified='2013-02-11'>
      <description>The "Do not provide Click to Add feature in calendar" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Do not provide Click to Add feature in calendar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12342-2' platform='office2010' modified='2013-02-11'>
      <description>The "First day of the week" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\First day of the week</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13966-7' platform='office2010' modified='2013-02-11'>
      <description>The "Include appointments only within working hours" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Include appointments only within working hours</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\pubcal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12319-0' platform='office2010' modified='2013-02-11'>
      <description>The "First week of year" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\First week of year</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13318-1' platform='office2010' modified='2013-02-11'>
      <description>The "Work week" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Work week</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12496-6' platform='office2010' modified='2013-02-11'>
      <description>The "Control Calendar Sharing" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Control Calendar Sharing</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12595-5' platform='office2010' modified='2013-02-11'>
      <description>The "Use this response when you propose new meeting times" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Use this response when you propose new meeting times</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13313-2' platform='office2010' modified='2013-02-11'>
      <description>The "Calendar week numbers" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Calendar week numbers</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14098-8' platform='office2010' modified='2013-02-11'>
      <description>The "Hide Send Latest Version button" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Hide Send Latest Version button</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11613-7' platform='office2010' modified='2013-02-11'>
      <description>The "Open Hyperlinks to documents in Windows Internet Explorer" machine PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft PowerPoint 2010 (Machine)\Miscellaneous\Open Hyperlinks to documents in Windows Internet Explorer</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\classes\powerpoint.slideshowmacroenabled.12</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13540-0' platform='office2010' modified='2013-02-11'>
      <description>The "Frequency for polling the server to download published links" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Server Settings\Frequency for polling the server to download published links</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\portal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13783-6' platform='office2010' modified='2013-02-11'>
      <description>The "Disable the user from setting the Personal Site URL" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Server Settings\Disable the user from setting the Personal Site URL</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\portal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12685-4' platform='office2010' modified='2013-02-11'>
      <description>The "Folder name for Published Links" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Server Settings\Folder name for Published Links</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\portal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14167-1' platform='office2010' modified='2013-02-11'>
      <description>The "Length AD Attribute containing Personal Site URL" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Server Settings\Length AD Attribute containing Personal Site URL</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\portal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13640-8' platform='office2010' modified='2013-02-11'>
      <description>The "Allow file synchronization via SOAP over HTTP only on domain networks" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Server Settings\Allow file synchronization via SOAP over HTTP only on domain networks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\fileio</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12860-3' platform='office2010' modified='2013-02-11'>
      <description>The "Disable the Office client from polling the SharePoint Server for published links" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Server Settings\Disable the Office client from polling the SharePoint Server for published links</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\portal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14606-8' platform='office2010' modified='2013-02-11'>
      <description>The "AD attribute containing Personal Site URL" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Server Settings\AD attribute containing Personal Site URL</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\portal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13381-9' platform='office2010' modified='2013-02-11'>
      <description>The "Suppress file format compatibility dialog box for OpenDocument Spreadsheet format" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Save\Suppress file format compatibility dialog box for OpenDocument Spreadsheet format</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13989-9' platform='office2010' modified='2013-02-11'>
      <description>The "AutoRecover delay" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Save\AutoRecover delay</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13420-5' platform='office2010' modified='2013-02-11'>
      <description>The "Default file location" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Save\Default file location</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14256-2' platform='office2010' modified='2013-02-11'>
      <description>The "Do not show AutoRepublish warning alert" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Save\Do not show AutoRepublish warning alert</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11502-2' platform='office2010' modified='2013-02-11'>
      <description>The "AutoRecover save location" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Save\AutoRecover save location</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12441-2' platform='office2010' modified='2013-02-11'>
      <description>The "Save date and time values using ISO 8601 date format" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Save\Save date and time values using ISO 8601 date format</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14355-2' platform='office2010' modified='2013-02-11'>
      <description>The "AutoRecover time" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Save\AutoRecover time</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14663-9' platform='office2010' modified='2013-02-11'>
      <description>The "Keep the last AutoSaved versions of files for the next session" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Save\Keep the last AutoSaved versions of files for the next session</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13822-2' platform='office2010' modified='2013-02-11'>
      <description>The "Save AutoRecover info" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Save\Save AutoRecover info</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12877-7' platform='office2010' modified='2013-02-11'>
      <description>The "Default file format" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Save\Default file format</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13161-5' platform='office2010' modified='2013-02-11'>
      <description>The "Prompt for workbook properties" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Save\Prompt for workbook properties</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options\binaryoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12144-2' platform='office2010' modified='2013-02-11'>
      <description>The "Disable AutoRepublish" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Save\Disable AutoRepublish</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14724-9' platform='office2010' modified='2013-02-11'>
      <description>The "Correct accidental usage of cAPS LOCK key" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Proofing\AutoCorrect\Correct accidental usage of cAPS LOCK key</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\assist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14497-2' platform='office2010' modified='2013-02-11'>
      <description>The "Correct TWo INitial CApitals" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Proofing\AutoCorrect\Correct TWo INitial CApitals</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\assist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13842-0' platform='office2010' modified='2013-02-11'>
      <description>The "Capitalize names of days" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Proofing\AutoCorrect\Capitalize names of days</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\assist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12898-3' platform='office2010' modified='2013-02-11'>
      <description>The "Replace text as you type" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Proofing\AutoCorrect\Replace text as you type</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\assist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14897-3' platform='office2010' modified='2013-02-11'>
      <description>The "Capitalize first letter of sentence" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Proofing\AutoCorrect\Capitalize first letter of sentence</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\assist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12101-2' platform='office2010' modified='2013-02-11'>
      <description>The "Correct keyboard setting" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Proofing\AutoCorrect\Correct keyboard setting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\assist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13324-9' platform='office2010' modified='2013-02-11'>
      <description>The "Outlook Security Mode" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Security Form Settings\Outlook Security Mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14248-9' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking to ensure hyperlink text is meaningful" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\File tab\Check Accessibility\Stop checking to ensure hyperlink text is meaningful</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12412-3' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking for blank table rows used as formatting" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\File tab\Check Accessibility\Stop checking for blank table rows used as formatting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12429-7' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking for table header accessibility information" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\File tab\Check Accessibility\Stop checking for table header accessibility information</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13444-5' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking to ensure non-default sheet names" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\File tab\Check Accessibility\Stop checking to ensure non-default sheet names</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13509-5' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking for alt text accessibility information" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\File tab\Check Accessibility\Stop checking for alt text accessibility information</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13385-0' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking for merged cells" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\File tab\Check Accessibility\Stop checking for merged cells</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12554-2' platform='office2010' modified='2013-02-11'>
      <description>The "Stop checking to ensure workbooks allow programmatic access" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\File tab\Check Accessibility\Stop checking to ensure workbooks allow programmatic access</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\accchecker</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12944-5' platform='office2010' modified='2013-02-11'>
      <description>The "Select the default setting for how to file new contacts" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Contact Options\Select the default setting for how to file new contacts</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\contact</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13528-5' platform='office2010' modified='2013-02-11'>
      <description>The "Show Contacts linking controls on all Forms" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Contact Options\Show Contacts linking controls on all Forms</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13767-9' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off contact export" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Contact Options\Turn off contact export</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12201-0' platform='office2010' modified='2013-02-11'>
      <description>The "Determine order of sources for photos" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Contact Options\Determine order of sources for photos</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12520-3' platform='office2010' modified='2013-02-11'>
      <description>The "Information Bar" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft Office 2010 (Machine)\Security Settings\IE Security\Information Bar</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\internet explorer\main\featurecontrol\feature_securityband</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13982-4' platform='office2010' modified='2013-02-11'>
      <description>The "Add-on Management" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft Office 2010 (Machine)\Security Settings\IE Security\Add-on Management</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\internet explorer\main\featurecontrol\feature_addon_management</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12359-6' platform='office2010' modified='2013-02-11'>
      <description>The "Restrict ActiveX Install" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft Office 2010 (Machine)\Security Settings\IE Security\Restrict ActiveX Install</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\internet explorer\main\featurecontrol\feature_restrict_activexinstall</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14125-9' platform='office2010' modified='2013-02-11'>
      <description>The "Saved from URL" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft Office 2010 (Machine)\Security Settings\IE Security\Saved from URL</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\internet explorer\main\featurecontrol\feature_unc_savedfilecheck</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14540-9' platform='office2010' modified='2013-02-11'>
      <description>The "Disable user name and password" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft Office 2010 (Machine)\Security Settings\IE Security\Disable user name and password</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\internet explorer\main\featurecontrol\feature_http_username_password_disable</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14328-9' platform='office2010' modified='2013-02-11'>
      <description>The "Block popups" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft Office 2010 (Machine)\Security Settings\IE Security\Block popups</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\internet explorer\main\featurecontrol\feature_weboc_popupmanagement</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14172-1' platform='office2010' modified='2013-02-11'>
      <description>The "Consistent Mime Handling" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft Office 2010 (Machine)\Security Settings\IE Security\Consistent Mime Handling</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\internet explorer\main\featurecontrol\feature_mime_handling</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14050-9' platform='office2010' modified='2013-02-11'>
      <description>The "Bind to object" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft Office 2010 (Machine)\Security Settings\IE Security\Bind to object</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\internet explorer\main\featurecontrol\feature_safe_bindtoobject</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13666-3' platform='office2010' modified='2013-02-11'>
      <description>The "Navigate URL" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft Office 2010 (Machine)\Security Settings\IE Security\Navigate URL</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\internet explorer\main\featurecontrol\feature_validate_navigate_url</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14358-6' platform='office2010' modified='2013-02-11'>
      <description>The "Object Caching Protection" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft Office 2010 (Machine)\Security Settings\IE Security\Object Caching Protection</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\internet explorer\main\featurecontrol\feature_object_caching</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12435-4' platform='office2010' modified='2013-02-11'>
      <description>The "Protection From Zone Elevation" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft Office 2010 (Machine)\Security Settings\IE Security\Protection From Zone Elevation</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\internet explorer\main\featurecontrol\feature_zone_elevation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13463-5' platform='office2010' modified='2013-02-11'>
      <description>The "Mime Sniffing Safety Feature" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft Office 2010 (Machine)\Security Settings\IE Security\Mime Sniffing Safety Feature</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\internet explorer\main\featurecontrol\feature_mime_sniffing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13709-1' platform='office2010' modified='2013-02-11'>
      <description>The "Restrict File Download" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft Office 2010 (Machine)\Security Settings\IE Security\Restrict File Download</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\internet explorer\main\featurecontrol\feature_restrict_filedownload</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14574-8' platform='office2010' modified='2013-02-11'>
      <description>The "Scripted Window Security Restrictions" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft Office 2010 (Machine)\Security Settings\IE Security\Scripted Window Security Restrictions</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\internet explorer\main\featurecontrol\feature_window_restrictions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13193-8' platform='office2010' modified='2013-02-11'>
      <description>The "Local Machine Zone Lockdown Security" machine setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft Office 2010 (Machine)\Security Settings\IE Security\Local Machine Zone Lockdown Security</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\internet explorer\main\featurecontrol\feature_localmachine_lockdown</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12710-0' platform='office2010' modified='2013-02-11'>
      <description>The "Replace AD attribute - "home phone"" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace AD attribute - "home phone"</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13332-2' platform='office2010' modified='2013-02-11'>
      <description>The "Replace Label - Location" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace Label - Location</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13957-6' platform='office2010' modified='2013-02-11'>
      <description>The "Replace MAPI property - "office location"" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace MAPI property - "office location"</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13720-8' platform='office2010' modified='2013-02-11'>
      <description>The "Replace MAPI property - "work phone"" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace MAPI property - "work phone"</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13234-0' platform='office2010' modified='2013-02-11'>
      <description>The "Replace AD attribute - "location information"" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace AD attribute - "location information"</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12351-3' platform='office2010' modified='2013-02-11'>
      <description>The "Replace AD attribute - "work phone"" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace AD attribute - "work phone"</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13316-5' platform='office2010' modified='2013-02-11'>
      <description>The "Replace Label - Work" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace Label - Work</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13301-7' platform='office2010' modified='2013-02-11'>
      <description>The "Move Calendar Line" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Move Calendar Line</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14015-2' platform='office2010' modified='2013-02-11'>
      <description>The "Replace AD attribute - "mobile phone"" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace AD attribute - "mobile phone"</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14013-7' platform='office2010' modified='2013-02-11'>
      <description>The "Replace AD attribute - "calendar free/busy information"" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace AD attribute - "calendar free/busy information"</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11918-0' platform='office2010' modified='2013-02-11'>
      <description>The "Replace AD attribute - "title, department"" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace AD attribute - "title, department"</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11462-9' platform='office2010' modified='2013-02-11'>
      <description>The "Replace Label - E-mail" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace Label - E-mail</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14522-7' platform='office2010' modified='2013-02-11'>
      <description>The "Replace AD attribute - "office location"" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace AD attribute - "office location"</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13243-1' platform='office2010' modified='2013-02-11'>
      <description>The "Replace MAPI property - "mobile phone"" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace MAPI property - "mobile phone"</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14049-1' platform='office2010' modified='2013-02-11'>
      <description>The "Replace MAPI property - "home phone"" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace MAPI property - "home phone"</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14628-2' platform='office2010' modified='2013-02-11'>
      <description>The "Replace Label - Mobile" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace Label - Mobile</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11894-3' platform='office2010' modified='2013-02-11'>
      <description>The "Replace MAPI property - "location information"" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace MAPI property - "location information"</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13086-4' platform='office2010' modified='2013-02-11'>
      <description>The "Replace MAPI property - "calendar free/busy information"" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace MAPI property - "calendar free/busy information"</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12469-3' platform='office2010' modified='2013-02-11'>
      <description>The "Replace MAPI property - "e-mail address"" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace MAPI property - "e-mail address"</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13740-6' platform='office2010' modified='2013-02-11'>
      <description>The "Replace Label - Office" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace Label - Office</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14492-3' platform='office2010' modified='2013-02-11'>
      <description>The "Replace Label - Title" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace Label - Title</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13069-0' platform='office2010' modified='2013-02-11'>
      <description>The "Replace AD attribute - "e-mail address"" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace AD attribute - "e-mail address"</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11979-2' platform='office2010' modified='2013-02-11'>
      <description>The "Replace MAPI property - "title,department"" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace MAPI property - "title,department"</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13900-6' platform='office2010' modified='2013-02-11'>
      <description>The "Move Location Line" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Move Location Line</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14148-1' platform='office2010' modified='2013-02-11'>
      <description>The "Replace Label - Home" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace Label - Home</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12331-5' platform='office2010' modified='2013-02-11'>
      <description>The "Replace Label - Calendar" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Contact Tab\Replace Label - Calendar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\contactcard</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12188-9' platform='office2010' modified='2013-02-11'>
      <description>The "Disable commands" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\Disable Items in User Interface\Predefined\Disable commands</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\disabledcmdbaritemscheckboxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14687-8' platform='office2010' modified='2013-02-11'>
      <description>The "Disable shortcut keys" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\Disable Items in User Interface\Predefined\Disable shortcut keys</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\disabledshortcutkeyscheckboxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13503-8' platform='office2010' modified='2013-02-11'>
      <description>The "Hide built in table styles" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\Disable Items in User Interface\Predefined\Hide built in table styles</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12183-0' platform='office2010' modified='2013-02-11'>
      <description>The "Do not open files in unsafe locations in Protected View" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\Protected View\Do not open files in unsafe locations in Protected View</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\protectedview</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14828-8' platform='office2010' modified='2013-02-11'>
      <description>The "Set document behavior if file validation fails" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\Protected View\Set document behavior if file validation fails</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\filevalidation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13024-5' platform='office2010' modified='2013-02-11'>
      <description>The "Do not open files from the Internet zone in Protected View" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\Protected View\Do not open files from the Internet zone in Protected View</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\protectedview</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11753-1' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Protected View for attachments opened from Outlook" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\Protected View\Turn off Protected View for attachments opened from Outlook</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\protectedview</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14204-2' platform='office2010' modified='2013-02-11'>
      <description>The "Open files on local Intranet UNC in Protected View" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Trust Center\Protected View\Open files on local Intranet UNC in Protected View</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\protectedview</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12458-6' platform='office2010' modified='2013-02-11'>
      <description>The "Show Mini Toolbar on selection" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\General\Show Mini Toolbar on selection</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\toolbars\powerpoint</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14754-6' platform='office2010' modified='2013-02-11'>
      <description>The "Enable Live Preview" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\General\Enable Live Preview</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13134-2' platform='office2010' modified='2013-02-11'>
      <description>The "Disable shortcut keys" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Disable Items in User Interface\Predefined\Disable shortcut keys</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\disabledshortcutkeyscheckboxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14131-7' platform='office2010' modified='2013-02-11'>
      <description>The "Disable commands" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Disable Items in User Interface\Predefined\Disable commands</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\disabledcmdbaritemscheckboxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13880-0' platform='office2010' modified='2013-02-11'>
      <description>The "Only containing an attachment" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Collaboration Settings\Default message text for a review request...\Only containing an attachment</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\reviewcycle</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13000-5' platform='office2010' modified='2013-02-11'>
      <description>The "Only containing a link" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Collaboration Settings\Default message text for a review request...\Only containing a link</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\reviewcycle</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11811-7' platform='office2010' modified='2013-02-11'>
      <description>The "Disable File Types association dialog box on first launch" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Microsoft Office Picture Manager\Disable File Types association dialog box on first launch</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ois</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12927-0' platform='office2010' modified='2013-02-11'>
      <description>The "Allow Trusted Locations on the network" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Allow Trusted Locations on the network</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12481-8' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #7" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Trusted Location #7</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations\location7</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12972-6' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #10" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Trusted Location #10</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations\location10</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13994-9' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #2" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Trusted Location #2</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations\location2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14297-6' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #17" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Trusted Location #17</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations\location17</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12059-2' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #16" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Trusted Location #16</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations\location16</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12704-3' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #9" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Trusted Location #9</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations\location9</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13959-2' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #6" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Trusted Location #6</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations\location6</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12767-0' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #15" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Trusted Location #15</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations\location15</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13741-4' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #20" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Trusted Location #20</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations\location20</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12438-8' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #13" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Trusted Location #13</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations\location13</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13816-4' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #11" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Trusted Location #11</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations\location11</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13300-9' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #14" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Trusted Location #14</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations\location14</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13566-5' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #1" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Trusted Location #1</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations\location1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12970-0' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #4" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Trusted Location #4</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations\location4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11963-6' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #3" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Trusted Location #3</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations\location3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13903-0' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #19" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Trusted Location #19</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations\location19</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14055-8' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #12" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Trusted Location #12</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations\location12</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12177-2' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #5" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Trusted Location #5</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations\location5</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13653-1' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #18" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Trusted Location #18</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations\location18</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13367-8' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #8" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Trusted Location #8</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations\location8</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13911-3' platform='office2010' modified='2013-02-11'>
      <description>The "Disable all trusted locations" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trusted Locations\Disable all trusted locations</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted locations</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13511-1' platform='office2010' modified='2013-02-11'>
      <description>The "Turn on an external converter as the default for a file extension" machine PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft PowerPoint 2010 (Machine)\Converters\Turn on an external converter as the default for a file extension</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\office\14.0\powerpoint\presentation converters\defaults</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11459-5' platform='office2010' modified='2013-02-11'>
      <description>The "Disable InfoPath e-mail forms in Outlook" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath e-mail forms\Disable InfoPath e-mail forms in Outlook</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14879-1' platform='office2010' modified='2013-02-11'>
      <description>The "Disable merging InfoPath e-mail forms" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath e-mail forms\Disable merging InfoPath e-mail forms</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\infopath</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13695-2' platform='office2010' modified='2013-02-11'>
      <description>The "Disable e-mail forms from the Full Trust security zone" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath e-mail forms\Disable e-mail forms from the Full Trust security zone</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13309-0' platform='office2010' modified='2013-02-11'>
      <description>The "Disable e-mail forms from the Intranet security zone" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath e-mail forms\Disable e-mail forms from the Intranet security zone</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12507-0' platform='office2010' modified='2013-02-11'>
      <description>The "Disable e-mail forms from the Internet security zone" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath e-mail forms\Disable e-mail forms from the Internet security zone</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13356-1' platform='office2010' modified='2013-02-11'>
      <description>The "Disable sending InfoPath 2003 Forms as e-mail forms" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath e-mail forms\Disable sending InfoPath 2003 Forms as e-mail forms</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14069-9' platform='office2010' modified='2013-02-11'>
      <description>The "Disable sending form template with e-mail forms" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath e-mail forms\Disable sending form template with e-mail forms</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\deployment</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14549-0' platform='office2010' modified='2013-02-11'>
      <description>The "Disable e-mail forms running in restricted security level" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath e-mail forms\Disable e-mail forms running in restricted security level</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14200-0' platform='office2010' modified='2013-02-11'>
      <description>The "Disable exporting InfoPath e-mail forms to Excel" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath e-mail forms\Disable exporting InfoPath e-mail forms to Excel</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\infopath</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14515-1' platform='office2010' modified='2013-02-11'>
      <description>The "Disable dynamic caching of the form template in InfoPath e-mail forms" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath e-mail forms\Disable dynamic caching of the form template in InfoPath e-mail forms</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\deployment</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11457-9' platform='office2010' modified='2013-02-11'>
      <description>The "Disable export InfoPath e-mail forms" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath e-mail forms\Disable export InfoPath e-mail forms</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\infopath</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12388-5' platform='office2010' modified='2013-02-11'>
      <description>The "Control behavior when opening InfoPath e-mail forms containing code or script" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath e-mail forms\Control behavior when opening InfoPath e-mail forms containing code or script</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12960-1' platform='office2010' modified='2013-02-11'>
      <description>The "Disable VBA for Office applications" machine common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft Office 2010 (Machine)\Security Settings\Disable VBA for Office applications</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\office\14.0\common</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13260-5' platform='office2010' modified='2013-02-11'>
      <description>The "Graphics filter import" machine common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft Office 2010 (Machine)\Security Settings\Graphics filter import</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\office\common\security\allowlists\graphicsfilterimport</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12559-1' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Password Caching" machine common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft Office 2010 (Machine)\Security Settings\Disable Password Caching</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\office\14.0\common\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12636-7' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Package Repair" machine common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>Computer Configuration\Administrative Templates\Microsoft Office 2010 (Machine)\Security Settings\Disable Package Repair</technical_mechanism>
        <technical_mechanism>HKEY_LOCAL_MACHINE\software\policies\microsoft\office\14.0\common\openxmlformat</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13752-1' platform='office2010' modified='2013-02-11'>
      <description>The "Approve Locations" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\File Open/Save dialog box\Restricted Browsing\Approve Locations</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\open find\restrictedbrowse</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13686-1' platform='office2010' modified='2013-02-11'>
      <description>The "Activate Restricted Browsing" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\File Open/Save dialog box\Restricted Browsing\Activate Restricted Browsing</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\open find\restrictedbrowse\optin</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13546-7' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Send and Track feature" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\E-mail Options\Tracking Options\Turn off Send and Track feature</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\flagging</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12365-3' platform='office2010' modified='2013-02-11'>
      <description>The "Options" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\E-mail Options\Tracking Options\Options</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13078-1' platform='office2010' modified='2013-02-11'>
      <description>The "Set User path for the label page size update files" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Shared paths\Set User path for the label page size update files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12194-7' platform='office2010' modified='2013-02-11'>
      <description>The "Shared themes path" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Shared paths\Shared themes path</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11975-0' platform='office2010' modified='2013-02-11'>
      <description>The "Set Workgroup path for label page size update files" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Shared paths\Set Workgroup path for label page size update files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13436-1' platform='office2010' modified='2013-02-11'>
      <description>The "Site 1:" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Global Options\Customize\Shared Workspace\Define Shared Workspace URL's\Site 1:</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\sharepointtracking\name0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13184-7' platform='office2010' modified='2013-02-11'>
      <description>The "Search for:" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Shape Search\Search for:</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13706-7' platform='office2010' modified='2013-02-11'>
      <description>The "Show Shape Search pane" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Shape Search\Show Shape Search pane</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13907-1' platform='office2010' modified='2013-02-11'>
      <description>The "Open results new window" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Shape Search\Open results new window</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14404-8' platform='office2010' modified='2013-02-11'>
      <description>The "Search results" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Shape Search\Search results</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14676-1' platform='office2010' modified='2013-02-11'>
      <description>The "Disable shortcut keys" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Disable Items in User Interface\Custom\Disable shortcut keys</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\disabledshortcutkeyslist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13953-5' platform='office2010' modified='2013-02-11'>
      <description>The "Disable commands" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Disable Items in User Interface\Custom\Disable commands</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\disabledcmdbaritemslist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13072-4' platform='office2010' modified='2013-02-11'>
      <description>The "Delete files from Office Document Cache" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Microsoft Office Document Cache\Delete files from Office Document Cache</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\fileio</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12111-1' platform='office2010' modified='2013-02-11'>
      <description>The "Check-out to local disk" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Microsoft Office Document Cache\Check-out to local disk</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\offline\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14636-5' platform='office2010' modified='2013-02-11'>
      <description>The "Office document cache location" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Microsoft Office Document Cache\Office document cache location</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\fileio</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12422-2' platform='office2010' modified='2013-02-11'>
      <description>The "Open documents from Office Document Cache first" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Microsoft Office Document Cache\Open documents from Office Document Cache first</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14743-9' platform='office2010' modified='2013-02-11'>
      <description>The "SharePoint Workspace Account Configuration Code Required" SharePoint Workspace setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft SharePoint Workspace 2010\SharePoint Workspace Account Configuration Code Required</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\groove</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14728-0' platform='office2010' modified='2013-02-11'>
      <description>The "List of blocked Groove relay servers" SharePoint Workspace setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft SharePoint Workspace 2010\List of blocked Groove relay servers</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\groove</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13700-0' platform='office2010' modified='2013-02-11'>
      <description>The "Prohibit Groove workspaces and Shared Folders" SharePoint Workspace setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft SharePoint Workspace 2010\Prohibit Groove workspaces and Shared Folders</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\groove</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13276-1' platform='office2010' modified='2013-02-11'>
      <description>The "Enable IPv6" SharePoint Workspace setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft SharePoint Workspace 2010\Enable IPv6</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\groove</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14099-6' platform='office2010' modified='2013-02-11'>
      <description>The "Set maximum number of proxy connection failures" SharePoint Workspace setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft SharePoint Workspace 2010\Set maximum number of proxy connection failures</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\groove</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12597-1' platform='office2010' modified='2013-02-11'>
      <description>The "Prefer IPv4" SharePoint Workspace setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft SharePoint Workspace 2010\Prefer IPv4</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\groove</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13225-8' platform='office2010' modified='2013-02-11'>
      <description>The "Groove Server Manager Valid Link Security" SharePoint Workspace setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft SharePoint Workspace 2010\Groove Server Manager Valid Link Security</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\groove</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14895-7' platform='office2010' modified='2013-02-11'>
      <description>The "VBA Macro Notification Settings" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\VBA Macro Notification Settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13027-8' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off trusted documents" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Turn off trusted documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted documents</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13222-5' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Data Execution Prevention" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Turn off Data Execution Prevention</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13459-3' platform='office2010' modified='2013-02-11'>
      <description>The "Set maximum number of trusted documents" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Set maximum number of trusted documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted documents</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13471-8' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Trusted Documents on the network" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Turn off Trusted Documents on the network</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted documents</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13014-6' platform='office2010' modified='2013-02-11'>
      <description>The "Set maximum number of trust records to preserve" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Set maximum number of trust records to preserve</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security\trusted documents</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13868-5' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Trust Bar Notification for unsigned application add-ins and block them" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Disable Trust Bar Notification for unsigned application add-ins and block them</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14916-1' platform='office2010' modified='2013-02-11'>
      <description>The "Disable all application add-ins" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Disable all application add-ins</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13220-9' platform='office2010' modified='2013-02-11'>
      <description>The "Require that application add-ins are signed by Trusted Publisher" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Application Settings\Security\Trust Center\Require that application add-ins are signed by Trusted Publisher</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14180-4' platform='office2010' modified='2013-02-11'>
      <description>The "Reminders" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\Advanced\Reminder Options\Reminders</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\reminders</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12861-1' platform='office2010' modified='2013-02-11'>
      <description>The "Save checked-out files to" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Save\Offline Editing\Save checked-out files to</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12619-3' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Quick Steps Gallery" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Disable Items in User Interface\Predefined\Disable Quick Steps Gallery</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13460-1' platform='office2010' modified='2013-02-11'>
      <description>The "Hide 'Shared Collections'" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Microsoft Clip Organizer\Hide 'Shared Collections'</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\clip organizer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13480-9' platform='office2010' modified='2013-02-11'>
      <description>The "Hide 'Office Collections'" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Microsoft Clip Organizer\Hide 'Office Collections'</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\clip organizer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13840-4' platform='office2010' modified='2013-02-11'>
      <description>The "Disable menu item: File | Add Clips To Organizer | From Scanner or Camera" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Microsoft Clip Organizer\Disable menu item: File | Add Clips To Organizer | From Scanner or Camera</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\clip organizer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13587-1' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent changes to primary collection" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Microsoft Clip Organizer\Prevent changes to primary collection</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\clip organizer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13581-4' platform='office2010' modified='2013-02-11'>
      <description>The "Clip Organizer Online URL" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Microsoft Clip Organizer\Clip Organizer Online URL</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\clip organizer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12849-6' platform='office2010' modified='2013-02-11'>
      <description>The "Enable preview of sound and motion on Terminal Server" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Microsoft Clip Organizer\Enable preview of sound and motion on Terminal Server</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\clip organizer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12335-6' platform='office2010' modified='2013-02-11'>
      <description>The "Search for clip art based on this language" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Microsoft Clip Organizer\Search for clip art based on this language</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\clip organizer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13551-7' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent access to online clip art" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Microsoft Clip Organizer\Prevent access to online clip art</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\clip organizer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12468-5' platform='office2010' modified='2013-02-11'>
      <description>The "Hide 'My Collections'" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Microsoft Clip Organizer\Hide 'My Collections'</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\clip organizer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13481-7' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent users from importing new clips" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Microsoft Clip Organizer\Prevent users from importing new clips</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\clip organizer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12957-7' platform='office2010' modified='2013-02-11'>
      <description>The "EKU filtering" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Signing\EKU filtering</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\signatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14208-3' platform='office2010' modified='2013-02-11'>
      <description>The "Set default image directory" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Signing\Set default image directory</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\signatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14301-6' platform='office2010' modified='2013-02-11'>
      <description>The "Legacy format signatures" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Signing\Legacy format signatures</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\signatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13019-5' platform='office2010' modified='2013-02-11'>
      <description>The "Key Usage Filtering" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Signing\Key Usage Filtering</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14906-2' platform='office2010' modified='2013-02-11'>
      <description>The "Set download location for Microsoft .NET Framework 2.0 Language Pack" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Downloading Framework Components\Set download location for Microsoft .NET Framework 2.0 Language Pack</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14516-9' platform='office2010' modified='2013-02-11'>
      <description>The "Set download location for Microsoft .NET Framework 2.0" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Downloading Framework Components\Set download location for Microsoft .NET Framework 2.0</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13424-7' platform='office2010' modified='2013-02-11'>
      <description>The "Set download location for Workflow component" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Downloading Framework Components\Set download location for Workflow component</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12928-8' platform='office2010' modified='2013-02-11'>
      <description>The "Hide missing component download hyperlinks" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Downloading Framework Components\Hide missing component download hyperlinks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12471-9' platform='office2010' modified='2013-02-11'>
      <description>The "Customize Active Directory search field for home phone lookup" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Instant Messaging Integration\Active Directory/person name action integration\Customize Active Directory search field for home phone lookup</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\personamenu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14008-7' platform='office2010' modified='2013-02-11'>
      <description>The "Customize Active Directory search field for primary telephone lookup" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Instant Messaging Integration\Active Directory/person name action integration\Customize Active Directory search field for primary telephone lookup</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\personamenu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14005-3' platform='office2010' modified='2013-02-11'>
      <description>The "Customize Active Directory search field for e-mail address lookup" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Instant Messaging Integration\Active Directory/person name action integration\Customize Active Directory search field for e-mail address lookup</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\personamenu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12801-7' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Active Directory lookups for the person name action" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Instant Messaging Integration\Active Directory/person name action integration\Disable Active Directory lookups for the person name action</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\personamenu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12302-6' platform='office2010' modified='2013-02-11'>
      <description>The "Customize Active Directory search field for office location lookup" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Instant Messaging Integration\Active Directory/person name action integration\Customize Active Directory search field for office location lookup</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\personamenu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12290-3' platform='office2010' modified='2013-02-11'>
      <description>The "Customize Active Directory search field for mobile phone lookup" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Instant Messaging Integration\Active Directory/person name action integration\Customize Active Directory search field for mobile phone lookup</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\personamenu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12521-1' platform='office2010' modified='2013-02-11'>
      <description>The "Customize Active Directory search field for manager lookup" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Instant Messaging Integration\Active Directory/person name action integration\Customize Active Directory search field for manager lookup</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\personamenu</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12940-3' platform='office2010' modified='2013-02-11'>
      <description>The "Run rules on RSS items" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\RSS Feeds\Run rules on RSS items</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\rss</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13174-8' platform='office2010' modified='2013-02-11'>
      <description>The "Synchronize Outlook RSS Feeds with Common Feed List" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\RSS Feeds\Synchronize Outlook RSS Feeds with Common Feed List</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\rss</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13111-0' platform='office2010' modified='2013-02-11'>
      <description>The "Automatically download enclosures" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\RSS Feeds\Automatically download enclosures</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\rss</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13446-0' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off RSS feature" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\RSS Feeds\Turn off RSS feature</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\rss</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13703-4' platform='office2010' modified='2013-02-11'>
      <description>The "Override published sync interval" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\RSS Feeds\Override published sync interval</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\rss</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13382-7' platform='office2010' modified='2013-02-11'>
      <description>The "Do not roam users' RSS Feeds" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\RSS Feeds\Do not roam users' RSS Feeds</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\rss</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12748-0' platform='office2010' modified='2013-02-11'>
      <description>The "Default RSS Feeds" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\RSS Feeds\Default RSS Feeds</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\accounts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14770-2' platform='office2010' modified='2013-02-11'>
      <description>The "Download full text of articles as HTML attachments" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\RSS Feeds\Download full text of articles as HTML attachments</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\rss</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12091-5' platform='office2010' modified='2013-02-11'>
      <description>The "Word 2007 and later documents and templates" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\File Block Settings\Word 2007 and later documents and templates</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14247-1' platform='office2010' modified='2013-02-11'>
      <description>The "Legacy converters for Word" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\File Block Settings\Legacy converters for Word</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12278-8' platform='office2010' modified='2013-02-11'>
      <description>The "RTF files" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\File Block Settings\RTF files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13680-4' platform='office2010' modified='2013-02-11'>
      <description>The "Word 2007 and later binary documents and templates" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\File Block Settings\Word 2007 and later binary documents and templates</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13311-6' platform='office2010' modified='2013-02-11'>
      <description>The "Word 2003 and plain XML documents" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\File Block Settings\Word 2003 and plain XML documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12995-7' platform='office2010' modified='2013-02-11'>
      <description>The "Word 2000 binary documents and templates" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\File Block Settings\Word 2000 binary documents and templates</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12769-6' platform='office2010' modified='2013-02-11'>
      <description>The "Office Open XML converters for Word" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\File Block Settings\Office Open XML converters for Word</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13774-5' platform='office2010' modified='2013-02-11'>
      <description>The "Set default file block behavior" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\File Block Settings\Set default file block behavior</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11535-2' platform='office2010' modified='2013-02-11'>
      <description>The "Word 95 binary documents and templates" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\File Block Settings\Word 95 binary documents and templates</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14333-9' platform='office2010' modified='2013-02-11'>
      <description>The "Word 2 and earlier binary documents and templates" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\File Block Settings\Word 2 and earlier binary documents and templates</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12612-8' platform='office2010' modified='2013-02-11'>
      <description>The "Word 2003 binary documents and templates" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\File Block Settings\Word 2003 binary documents and templates</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13057-5' platform='office2010' modified='2013-02-11'>
      <description>The "OpenDocument Text files" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\File Block Settings\OpenDocument Text files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12153-3' platform='office2010' modified='2013-02-11'>
      <description>The "Web pages" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\File Block Settings\Web pages</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13323-1' platform='office2010' modified='2013-02-11'>
      <description>The "Word beta converters" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\File Block Settings\Word beta converters</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13565-7' platform='office2010' modified='2013-02-11'>
      <description>The "Word XP binary documents and templates" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\File Block Settings\Word XP binary documents and templates</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12715-9' platform='office2010' modified='2013-02-11'>
      <description>The "Word 6.0 binary documents and templates" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\File Block Settings\Word 6.0 binary documents and templates</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13548-3' platform='office2010' modified='2013-02-11'>
      <description>The "Word beta files" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\File Block Settings\Word beta files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13262-1' platform='office2010' modified='2013-02-11'>
      <description>The "Word 97 binary documents and templates" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\File Block Settings\Word 97 binary documents and templates</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12239-0' platform='office2010' modified='2013-02-11'>
      <description>The "Plain text files" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\File Block Settings\Plain text files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12766-2' platform='office2010' modified='2013-02-11'>
      <description>The "Print TrueType fonts as graphics" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Advanced\Print TrueType fonts as graphics</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12929-6' platform='office2010' modified='2013-02-11'>
      <description>The "When selecting, automatically select entire word" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Advanced\When selecting, automatically select entire word</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14339-6' platform='office2010' modified='2013-02-11'>
      <description>The "Use smart cut and paste" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Advanced\Use smart cut and paste</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12245-7' platform='office2010' modified='2013-02-11'>
      <description>The "End with black slide" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Advanced\End with black slide</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11786-1' platform='office2010' modified='2013-02-11'>
      <description>The "Print in background" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Advanced\Print in background</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12267-1' platform='office2010' modified='2013-02-11'>
      <description>The "Show all windows in the Taskbar" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Advanced\Show all windows in the Taskbar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13172-2' platform='office2010' modified='2013-02-11'>
      <description>The "Show popup toolbar" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Advanced\Show popup toolbar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14456-8' platform='office2010' modified='2013-02-11'>
      <description>The "Print inserted objects at printer resolution" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Advanced\Print inserted objects at printer resolution</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12707-6' platform='office2010' modified='2013-02-11'>
      <description>The "Set default number of documents in the Recent Documents list" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Advanced\Set default number of documents in the Recent Documents list</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\file mru</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12556-7' platform='office2010' modified='2013-02-11'>
      <description>The "Show vertical ruler" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Advanced\Show vertical ruler</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13426-2' platform='office2010' modified='2013-02-11'>
      <description>The "Show menu on right mouse click" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Advanced\Show menu on right mouse click</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12698-7' platform='office2010' modified='2013-02-11'>
      <description>The "Allow text to be dragged and dropped" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Advanced\Allow text to be dragged and dropped</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13713-3' platform='office2010' modified='2013-02-11'>
      <description>The "Maximum number of undos" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Advanced\Maximum number of undos</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14128-3' platform='office2010' modified='2013-02-11'>
      <description>The "Set number of places in the Recent Places list" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Advanced\Set number of places in the Recent Places list</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\place mru</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12211-9' platform='office2010' modified='2013-02-11'>
      <description>The "Rely on VML for displaying graphics in browsers" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Tools | Options | General | Web Options...\Browsers\Rely on VML for displaying graphics in browsers</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13571-5' platform='office2010' modified='2013-02-11'>
      <description>The "Allow PNG as an output format" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Tools | Options | General | Web Options...\Browsers\Allow PNG as an output format</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13477-5' platform='office2010' modified='2013-02-11'>
      <description>The "Default unit of measurement used in OneNote" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Other\Default unit of measurement used in OneNote</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\other</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12281-2' platform='office2010' modified='2013-02-11'>
      <description>The "Disable embedded files" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Other\Disable embedded files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14222-4' platform='office2010' modified='2013-02-11'>
      <description>The "Add OneNote icon to notification area" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Other\Add OneNote icon to notification area</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\other</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13286-0' platform='office2010' modified='2013-02-11'>
      <description>The "Load a notebook on first boot" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Other\Load a notebook on first boot</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\other</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13433-8' platform='office2010' modified='2013-02-11'>
      <description>The "Disable OneNote screen clipping notifications" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Other\Disable OneNote screen clipping notifications</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\other</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13211-8' platform='office2010' modified='2013-02-11'>
      <description>The "Disable OneNote Screen Clippings" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Other\Disable OneNote Screen Clippings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\other</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12897-5' platform='office2010' modified='2013-02-11'>
      <description>The "Number of days before warning that server is inaccessible" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Other\Number of days before warning that server is inaccessible</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\synchronization</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13533-5' platform='office2010' modified='2013-02-11'>
      <description>The "Embedded Files Blocked Extensions" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Other\Embedded Files Blocked Extensions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\embeddedfileopenoptions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14478-2' platform='office2010' modified='2013-02-11'>
      <description>The "Disable OCR" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Other\Disable OCR</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\other</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14409-7' platform='office2010' modified='2013-02-11'>
      <description>The "SharePoint sync interval for notebooks stored on SharePoint" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Other\SharePoint sync interval for notebooks stored on SharePoint</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\save</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13070-8' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off OneNote auto-linked note taking" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Other\Turn off OneNote auto-linked note taking</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\linkednotes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14518-5' platform='office2010' modified='2013-02-11'>
      <description>The "Set UNC interval to poll for changes on file servers" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Other\Set UNC interval to poll for changes on file servers</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\save</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12644-1' platform='office2010' modified='2013-02-11'>
      <description>The "Do not permit download of content from safe zones" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Automatic Picture Download Settings\Do not permit download of content from safe zones</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12126-9' platform='office2010' modified='2013-02-11'>
      <description>The "Include Intranet in Safe Zones for Automatic Picture Download" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Automatic Picture Download Settings\Include Intranet in Safe Zones for Automatic Picture Download</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13002-1' platform='office2010' modified='2013-02-11'>
      <description>The "Display pictures and external content in HTML e-mail" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Automatic Picture Download Settings\Display pictures and external content in HTML e-mail</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14157-2' platform='office2010' modified='2013-02-11'>
      <description>The "Include Internet in Safe Zones for Automatic Picture Download" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Automatic Picture Download Settings\Include Internet in Safe Zones for Automatic Picture Download</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14610-0' platform='office2010' modified='2013-02-11'>
      <description>The "Automatically download content for e-mail from people in Safe Senders and Safe Recipients Lists" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Automatic Picture Download Settings\Automatically download content for e-mail from people in Safe Senders and Safe Recipients Lists</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12621-9' platform='office2010' modified='2013-02-11'>
      <description>The "Block Trusted Zones" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Automatic Picture Download Settings\Block Trusted Zones</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14065-7' platform='office2010' modified='2013-02-11'>
      <description>The "Change the limit for the number of characters in Friendly Name" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\MIME to MAPI Conversion\Change the limit for the number of characters in Friendly Name</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13951-9' platform='office2010' modified='2013-02-11'>
      <description>The "Change the limit for the number of recipients" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\MIME to MAPI Conversion\Change the limit for the number of recipients</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14441-0' platform='office2010' modified='2013-02-11'>
      <description>The "Change the limit for the number of MIME body parts" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\MIME to MAPI Conversion\Change the limit for the number of MIME body parts</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13768-7' platform='office2010' modified='2013-02-11'>
      <description>The "Change the limit for the number of MIME headers" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\MIME to MAPI Conversion\Change the limit for the number of MIME headers</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13949-3' platform='office2010' modified='2013-02-11'>
      <description>The "Change the limit for the number of nested embedded messages" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\MIME to MAPI Conversion\Change the limit for the number of nested embedded messages</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12683-9' platform='office2010' modified='2013-02-11'>
      <description>The "Font" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\General\Font</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14875-9' platform='office2010' modified='2013-02-11'>
      <description>The "Show Mini Toolbar on selection" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\General\Show Mini Toolbar on selection</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\toolbars\excel</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13266-2' platform='office2010' modified='2013-02-11'>
      <description>The "Show all windows in the Taskbar" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\General\Show all windows in the Taskbar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13406-4' platform='office2010' modified='2013-02-11'>
      <description>The "Default Sheets" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\General\Default Sheets</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12949-4' platform='office2010' modified='2013-02-11'>
      <description>The "Enable Live Preview" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\General\Enable Live Preview</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12427-1' platform='office2010' modified='2013-02-11'>
      <description>The "Access to published calendars" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\OFfice.com Sharing Service\Access to published calendars</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\pubcal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13449-4' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent publishing to Office.com" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\OFfice.com Sharing Service\Prevent publishing to Office.com</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\pubcal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12379-4' platform='office2010' modified='2013-02-11'>
      <description>The "Publish interval" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\OFfice.com Sharing Service\Publish interval</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\pubcal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13431-2' platform='office2010' modified='2013-02-11'>
      <description>The "Path to DAV server" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\OFfice.com Sharing Service\Path to DAV server</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\pubcal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13555-8' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent publishing to a DAV server" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\OFfice.com Sharing Service\Prevent publishing to a DAV server</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\pubcal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14129-1' platform='office2010' modified='2013-02-11'>
      <description>The "Restrict upload method" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\OFfice.com Sharing Service\Restrict upload method</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\pubcal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13058-3' platform='office2010' modified='2013-02-11'>
      <description>The "Restrict level of calendar details users can publish" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\OFfice.com Sharing Service\Restrict level of calendar details users can publish</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\pubcal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12324-0' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off file validation" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Turn off file validation</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\filevalidation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12405-7' platform='office2010' modified='2013-02-11'>
      <description>The "Perform file validation on pivot caches" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Perform file validation on pivot caches</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\filevalidation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12387-7' platform='office2010' modified='2013-02-11'>
      <description>The "Scan encrypted macros in Excel Open XML workbooks" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Scan encrypted macros in Excel Open XML workbooks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14532-6' platform='office2010' modified='2013-02-11'>
      <description>The "Force file extension to match file type" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Excel 2010\Excel Options\Security\Force file extension to match file type</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12648-2' platform='office2010' modified='2013-02-11'>
      <description>The "Allow file types as attachments to forms" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Security\Allow file types as attachments to forms</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12369-5' platform='office2010' modified='2013-02-11'>
      <description>The "Disable fully trusted solutions full access to computer" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Security\Disable fully trusted solutions full access to computer</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12436-2' platform='office2010' modified='2013-02-11'>
      <description>The "Control behavior for Microsoft SharePoint Foundation gradual upgrade" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Security\Control behavior for Microsoft SharePoint Foundation gradual upgrade</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13438-7' platform='office2010' modified='2013-02-11'>
      <description>The "Block specific file types as attachments to forms" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Security\Block specific file types as attachments to forms</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12719-1' platform='office2010' modified='2013-02-11'>
      <description>The "Beaconing UI for forms opened in InfoPath" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Security\Beaconing UI for forms opened in InfoPath</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12808-2' platform='office2010' modified='2013-02-11'>
      <description>The "Display a warning that a form is digitally signed" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Security\Display a warning that a form is digitally signed</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12906-4' platform='office2010' modified='2013-02-11'>
      <description>The "Beaconing UI for forms opened in InfoPath Filler ActiveX" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Security\Beaconing UI for forms opened in InfoPath Filler ActiveX</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13157-3' platform='office2010' modified='2013-02-11'>
      <description>The "Disable opening of solutions from the Internet security zone" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Security\Disable opening of solutions from the Internet security zone</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12285-3' platform='office2010' modified='2013-02-11'>
      <description>The "Disable opening forms with managed code from the Internet security zone" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Security\Disable opening forms with managed code from the Internet security zone</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12668-0' platform='office2010' modified='2013-02-11'>
      <description>The "Allow the use of ActiveX Custom Controls in InfoPath forms" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Security\Allow the use of ActiveX Custom Controls in InfoPath forms</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13473-4' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent users from allowing unsafe file types to be attached to forms" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Security\Prevent users from allowing unsafe file types to be attached to forms</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13489-0' platform='office2010' modified='2013-02-11'>
      <description>The "Detect language automatically" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Review Tab\Language | Set Proofing Language...\Detect language automatically</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13191-2' platform='office2010' modified='2013-02-11'>
      <description>The "List of error messages to customize" Access setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Access 2010\Customizable Error Messages\List of error messages to customize</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\access\customizablealerts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14458-4' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off file synchronization via SOAP over HTTP" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\Miscellaneous\Server Settings\Turn off file synchronization via SOAP over HTTP</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14315-6' platform='office2010' modified='2013-02-11'>
      <description>The "Auto Keyboard Switching" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Editing\Auto Keyboard Switching</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\language</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13179-7' platform='office2010' modified='2013-02-11'>
      <description>The "Auto Numbering Recognition" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Editing\Auto Numbering Recognition</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\editing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12573-2' platform='office2010' modified='2013-02-11'>
      <description>The "Default Font Size" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Editing\Default Font Size</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\editing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13435-3' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off link creation with [[ ]]" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Editing\Turn off link creation with [[ ]]</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\editing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14078-0' platform='office2010' modified='2013-02-11'>
      <description>The "Show Paste Options buttons" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Editing\Show Paste Options buttons</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\other</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13855-2' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off auto calculator" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Editing\Turn off auto calculator</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\editing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13077-3' platform='office2010' modified='2013-02-11'>
      <description>The "Auto Bullet Recognition" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Editing\Auto Bullet Recognition</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\editing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13492-4' platform='office2010' modified='2013-02-11'>
      <description>The "Include link to source when pasting from the Internet" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Editing\Include link to source when pasting from the Internet</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\editing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13253-0' platform='office2010' modified='2013-02-11'>
      <description>The "Default Font Name" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Editing\Default Font Name</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\editing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13232-4' platform='office2010' modified='2013-02-11'>
      <description>The "Polling Out-of-office Web service" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Out of Office Assistant\Polling Out-of-office Web service</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\oof</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12476-8' platform='office2010' modified='2013-02-11'>
      <description>The "Do not display the reading pane" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\Do not display the reading pane</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14198-6' platform='office2010' modified='2013-02-11'>
      <description>The "Make Outlook the default program for E-mail, Contacts, and Calendar" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\Make Outlook the default program for E-mail, Contacts, and Calendar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14353-7' platform='office2010' modified='2013-02-11'>
      <description>The "Do not download photos from the Active Directory" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\Do not download photos from the Active Directory</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\contact</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13164-9' platform='office2010' modified='2013-02-11'>
      <description>The "Print dark categories" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\Print dark categories</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\printing</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13126-8' platform='office2010' modified='2013-02-11'>
      <description>The "Empty the Deleted Items folder when Outlook closes" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\Empty the Deleted Items folder when Outlook closes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12629-2' platform='office2010' modified='2013-02-11'>
      <description>The "Reading Pane" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\Reading Pane</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12919-7' platform='office2010' modified='2013-02-11'>
      <description>The "Hide photo link" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\Hide photo link</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13203-5' platform='office2010' modified='2013-02-11'>
      <description>The "Show Mini Toolbar on selection" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Other\Show Mini Toolbar on selection</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\toolbars\outlook</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13525-1' platform='office2010' modified='2013-02-11'>
      <description>The "Enter seconds to wait to download changes from server" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Cached Exchange Mode\Enter seconds to wait to download changes from server</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\cached mode</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14659-7' platform='office2010' modified='2013-02-11'>
      <description>The "Enter seconds to wait to upload changes to server" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Cached Exchange Mode\Enter seconds to wait to upload changes to server</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\cached mode</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11927-1' platform='office2010' modified='2013-02-11'>
      <description>The "Disallow Download Full Items" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Cached Exchange Mode\Disallow Download Full Items</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\cached mode</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13517-8' platform='office2010' modified='2013-02-11'>
      <description>The "Download Public Folder Favorites" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Cached Exchange Mode\Download Public Folder Favorites</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\cached mode</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13631-7' platform='office2010' modified='2013-02-11'>
      <description>The "Disallow Download Headers" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Cached Exchange Mode\Disallow Download Headers</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\cached mode</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12789-4' platform='office2010' modified='2013-02-11'>
      <description>The "Enter maximum seconds to wait to sync changes" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Cached Exchange Mode\Enter maximum seconds to wait to sync changes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\cached mode</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12660-7' platform='office2010' modified='2013-02-11'>
      <description>The "Cached Exchange Mode (File | Cached Exchange Mode)" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Cached Exchange Mode\Cached Exchange Mode (File | Cached Exchange Mode)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\cached mode</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14920-3' platform='office2010' modified='2013-02-11'>
      <description>The "Disallow Download Headers then Full Items" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Cached Exchange Mode\Disallow Download Headers then Full Items</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\cached mode</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12279-6' platform='office2010' modified='2013-02-11'>
      <description>The "Download shared non-mail folders" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Cached Exchange Mode\Download shared non-mail folders</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\cached mode</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13087-2' platform='office2010' modified='2013-02-11'>
      <description>The "Use Cached Exchange Mode for new and existing Outlook profiles" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Cached Exchange Mode\Use Cached Exchange Mode for new and existing Outlook profiles</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\cached mode</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14060-8' platform='office2010' modified='2013-02-11'>
      <description>The "Do not sync in Cached Exchange mode when users click Send/Receive or F9" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Cached Exchange Mode\Do not sync in Cached Exchange mode when users click Send/Receive or F9</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\cached mode</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14702-5' platform='office2010' modified='2013-02-11'>
      <description>The "Disallow On Slow Connections Only Download Headers" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Cached Exchange Mode\Disallow On Slow Connections Only Download Headers</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\cached mode</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13687-9' platform='office2010' modified='2013-02-11'>
      <description>The "Specify ScreenTips to appear" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Display\Specify ScreenTips to appear</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14218-2' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent showing New screen on launch" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Display\Prevent showing New screen on launch</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14364-4' platform='office2010' modified='2013-02-11'>
      <description>The "Stencil window ScreenTips" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Display\Stencil window ScreenTips</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14650-6' platform='office2010' modified='2013-02-11'>
      <description>The "Actions" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Display\Actions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13417-1' platform='office2010' modified='2013-02-11'>
      <description>The "Duration" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Display\Duration</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\document</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12856-1' platform='office2010' modified='2013-02-11'>
      <description>The "Always offer 'Metric' and 'US units' for new blank drawings and stencils" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Display\Always offer 'Metric' and 'US units' for new blank drawings and stencils</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14057-4' platform='office2010' modified='2013-02-11'>
      <description>The "Angle" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Display\Angle</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\document</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14332-1' platform='office2010' modified='2013-02-11'>
      <description>The "Text" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Advanced\Display\Text</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\document</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12659-9' platform='office2010' modified='2013-02-11'>
      <description>The "Save Visio files as" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Save\Save Documents\Save Visio files as</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12501-3' platform='office2010' modified='2013-02-11'>
      <description>The "Prompt for document properties on first save" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Save\Save Documents\Prompt for document properties on first save</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\application</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14689-4' platform='office2010' modified='2013-02-11'>
      <description>The "Followed hyperlink color" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Edit\Hyperlink appearance in 'Project1'\Followed hyperlink color</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\edit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13524-4' platform='office2010' modified='2013-02-11'>
      <description>The "Hyperlink color" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Edit\Hyperlink appearance in 'Project1'\Hyperlink color</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\edit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14347-9' platform='office2010' modified='2013-02-11'>
      <description>The "Underline hyperlinks" Project setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Project 2010\Project Options\Edit\Hyperlink appearance in 'Project1'\Underline hyperlinks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\ms project\options\edit</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13144-1' platform='office2010' modified='2013-02-11'>
      <description>The "Rely on CSS for font formatting" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Tools | Options | General | Web Options...\General\Rely on CSS for font formatting</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13357-9' platform='office2010' modified='2013-02-11'>
      <description>The "Configure trusted add-ins" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Security Form Settings\Programmatic Security\Trusted Add-ins\Configure trusted add-ins</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security\trustedaddins</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13352-0' platform='office2010' modified='2013-02-11'>
      <description>The "Use legacy Change Password authentication dialog boxes" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Use legacy Change Password authentication dialog boxes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\rpc</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12537-7' platform='office2010' modified='2013-02-11'>
      <description>The "Exchange Unicode Mode - Turn off ANSI mode" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Exchange Unicode Mode - Turn off ANSI mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\emsp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13083-1' platform='office2010' modified='2013-02-11'>
      <description>The "Set maximum number of Exchange accounts per profile" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Set maximum number of Exchange accounts per profile</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\exchange</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13241-5' platform='office2010' modified='2013-02-11'>
      <description>The "Authentication with Exchange Server" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Authentication with Exchange Server</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12768-8' platform='office2010' modified='2013-02-11'>
      <description>The "Restrict legacy Exchange account" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Restrict legacy Exchange account</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\exchange</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14888-2' platform='office2010' modified='2013-02-11'>
      <description>The "Exchange Unicode Mode - Ignore OST Format" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Exchange Unicode Mode - Ignore OST Format</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\emsp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13778-6' platform='office2010' modified='2013-02-11'>
      <description>The "Do not allow users to change permissions on folders" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Do not allow users to change permissions on folders</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\folders</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12372-9' platform='office2010' modified='2013-02-11'>
      <description>The "Do not display Folder Size button on folder properties dialog box" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Do not display Folder Size button on folder properties dialog box</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13278-7' platform='office2010' modified='2013-02-11'>
      <description>The "Synchronizing data in shared folders" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Synchronizing data in shared folders</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\cached mode</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13714-1' platform='office2010' modified='2013-02-11'>
      <description>The "Specify exceptions for DisableCrossAccountCopy" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Specify exceptions for DisableCrossAccountCopy</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11504-8' platform='office2010' modified='2013-02-11'>
      <description>The "Cached Exchange low bandwidth threshold" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Cached Exchange low bandwidth threshold</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\rpc</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13667-1' platform='office2010' modified='2013-02-11'>
      <description>The "Automatically configure profile based on Active Directory Primary SMTP address" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Automatically configure profile based on Active Directory Primary SMTP address</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\autodiscover</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13233-2' platform='office2010' modified='2013-02-11'>
      <description>The "Do not allow an OST file to be created" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Do not allow an OST file to be created</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\ost</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13674-7' platform='office2010' modified='2013-02-11'>
      <description>The "Enable RPC encryption" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Enable RPC encryption</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\rpc</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13335-5' platform='office2010' modified='2013-02-11'>
      <description>The "Do not validate personal Contact Groups when sending e-mail messages" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Do not validate personal Contact Groups when sending e-mail messages</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13152-4' platform='office2010' modified='2013-02-11'>
      <description>The "Exchange Unicode Mode - Silent OST format change" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Exchange Unicode Mode - Silent OST format change</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\emsp</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12547-6' platform='office2010' modified='2013-02-11'>
      <description>The "Configure Outlook Anywhere user interface options" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Configure Outlook Anywhere user interface options</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\rpc</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13150-8' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent copying or moving items between accounts" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Prevent copying or moving items between accounts</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13970-9' platform='office2010' modified='2013-02-11'>
      <description>The "Set default file block behavior" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\File Block Settings\Set default file block behavior</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14523-5' platform='office2010' modified='2013-02-11'>
      <description>The "PowerPoint 97-2003 presentations, shows, templates and add-in files" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\File Block Settings\PowerPoint 97-2003 presentations, shows, templates and add-in files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13402-3' platform='office2010' modified='2013-02-11'>
      <description>The "Outline files" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\File Block Settings\Outline files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12093-1' platform='office2010' modified='2013-02-11'>
      <description>The "PowerPoint beta converters" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\File Block Settings\PowerPoint beta converters</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13302-5' platform='office2010' modified='2013-02-11'>
      <description>The "Microsoft Office Open XML converters for PowerPoint" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\File Block Settings\Microsoft Office Open XML converters for PowerPoint</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14467-5' platform='office2010' modified='2013-02-11'>
      <description>The "Web Pages" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\File Block Settings\Web Pages</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13430-4' platform='office2010' modified='2013-02-11'>
      <description>The "PowerPoint beta files" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\File Block Settings\PowerPoint beta files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13336-3' platform='office2010' modified='2013-02-11'>
      <description>The "Graphic Filters" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\File Block Settings\Graphic Filters</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13722-4' platform='office2010' modified='2013-02-11'>
      <description>The "Legacy converters for PowerPoint" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\File Block Settings\Legacy converters for PowerPoint</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14382-6' platform='office2010' modified='2013-02-11'>
      <description>The "OpenDocument Presentation files" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\File Block Settings\OpenDocument Presentation files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11830-7' platform='office2010' modified='2013-02-11'>
      <description>The "PowerPoint 2007 and later presentations, shows, templates, themes and add-in files" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\File Block Settings\PowerPoint 2007 and later presentations, shows, templates, themes and add-in files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13875-0' platform='office2010' modified='2013-02-11'>
      <description>The "Merge formatting when pasting from PowerPoint" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Smart cut and paste\Merge formatting when pasting from PowerPoint</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12992-4' platform='office2010' modified='2013-02-11'>
      <description>The "Adjust formatting when pasting from Microsoft Excel" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Smart cut and paste\Adjust formatting when pasting from Microsoft Excel</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12552-6' platform='office2010' modified='2013-02-11'>
      <description>The "Adjust table formatting and alignment on paste" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Smart cut and paste\Adjust table formatting and alignment on paste</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12041-0' platform='office2010' modified='2013-02-11'>
      <description>The "Smart style behavior" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Smart cut and paste\Smart style behavior</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11680-6' platform='office2010' modified='2013-02-11'>
      <description>The "Merge pasted lists with surrounding lists" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Smart cut and paste\Merge pasted lists with surrounding lists</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14717-3' platform='office2010' modified='2013-02-11'>
      <description>The "Adjust sentence and word spacing automatically" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Smart cut and paste\Adjust sentence and word spacing automatically</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11803-4' platform='office2010' modified='2013-02-11'>
      <description>The "Adjust paragraph spacing on paste" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\Smart cut and paste\Adjust paragraph spacing on paste</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14314-9' platform='office2010' modified='2013-02-11'>
      <description>The "Disable password protected sections" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Password\Disable password protected sections</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11550-1' platform='office2010' modified='2013-02-11'>
      <description>The "Lock password protected sections after user hasn't worked on them for a time" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Password\Lock password protected sections after user hasn't worked on them for a time</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12207-7' platform='office2010' modified='2013-02-11'>
      <description>The "Lock password protected sections as soon as I navigate away from them" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Password\Lock password protected sections as soon as I navigate away from them</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14531-8' platform='office2010' modified='2013-02-11'>
      <description>The "Disallows add-ons access to password protected sections" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Password\Disallows add-ons access to password protected sections</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12368-7' platform='office2010' modified='2013-02-11'>
      <description>The "Trust access to Visual Basic Project" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Trust access to Visual Basic Project</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13294-4' platform='office2010' modified='2013-02-11'>
      <description>The "Scan encrypted macros in Word Open XML documents" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Scan encrypted macros in Word Open XML documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13769-5' platform='office2010' modified='2013-02-11'>
      <description>The "Disable all application add-ins" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Disable all application add-ins</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13268-8' platform='office2010' modified='2013-02-11'>
      <description>The "Require that application add-ins are signed by Trusted Publisher" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Require that application add-ins are signed by Trusted Publisher</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14035-0' platform='office2010' modified='2013-02-11'>
      <description>The "Set maximum number of trusted documents" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Set maximum number of trusted documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted documents</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12577-3' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Data Execution Prevention" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Turn off Data Execution Prevention</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13887-5' platform='office2010' modified='2013-02-11'>
      <description>The "Set maximum number of trust records to preserve" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Set maximum number of trust records to preserve</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted documents</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13182-1' platform='office2010' modified='2013-02-11'>
      <description>The "VBA Macro Notification Settings" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\VBA Macro Notification Settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14249-7' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off trusted documents" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Turn off trusted documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted documents</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14053-3' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Trusted Documents on the network" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Turn off Trusted Documents on the network</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\trusted documents</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13705-9' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Trust Bar Notification for unsigned application add-ins and block them" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Security\Trust Center\Disable Trust Bar Notification for unsigned application add-ins and block them</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12578-1' platform='office2010' modified='2013-02-11'>
      <description>The "Resize graphics to fit browser window" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Advanced\Web Options...\General\Resize graphics to fit browser window</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12820-7' platform='office2010' modified='2013-02-11'>
      <description>The "Slide navigation" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Advanced\Web Options...\General\Slide navigation</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13579-8' platform='office2010' modified='2013-02-11'>
      <description>The "Show slide animation while browsing" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Advanced\Web Options...\General\Show slide animation while browsing</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11619-4' platform='office2010' modified='2013-02-11'>
      <description>The "Offline Address Book: Limit manual OAB downloads" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Offline Address Book\Offline Address Book: Limit manual OAB downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\exchange\exchange provider</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13110-2' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Hierarchical Address Book search" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Offline Address Book\Turn off Hierarchical Address Book search</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14203-4' platform='office2010' modified='2013-02-11'>
      <description>The "Return e-mail alias if it exactly matches the provided e-mail address when searching OAB" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Offline Address Book\Return e-mail alias if it exactly matches the provided e-mail address when searching OAB</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\exchange\exchange provider</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14500-3' platform='office2010' modified='2013-02-11'>
      <description>The "Offline Address Book: Limit number of incremental OAB downloads" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Offline Address Book\Offline Address Book: Limit number of incremental OAB downloads</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\exchange\exchange provider</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12128-5' platform='office2010' modified='2013-02-11'>
      <description>The "Display option for downloading OAB changes since last Send/Receive" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Offline Address Book\Display option for downloading OAB changes since last Send/Receive</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\exchange\exchange provider</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14912-0' platform='office2010' modified='2013-02-11'>
      <description>The "Offline Address Book: Prompt before Downloading Full OAB" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Offline Address Book\Offline Address Book: Prompt before Downloading Full OAB</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\exchange\exchange provider</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13325-6' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Hierarchical Address Book" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Offline Address Book\Turn off Hierarchical Address Book</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13860-2' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Hierarchical Address Book department selection" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Offline Address Book\Turn off Hierarchical Address Book department selection</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12513-8' platform='office2010' modified='2013-02-11'>
      <description>The "Use only OAB v4" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Account Settings\Exchange\Offline Address Book\Use only OAB v4</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\exchange\exchange provider</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12364-6' platform='office2010' modified='2013-02-11'>
      <description>The "Mail account options" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Mail Setup\Mail account options</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12931-2' platform='office2010' modified='2013-02-11'>
      <description>The "Dial-up options" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Mail Setup\Dial-up options</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\mail</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13440-3' platform='office2010' modified='2013-02-11'>
      <description>The "Smiley faces and arrows with special symbols" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Proofing\AutoCorrect Options\Smiley faces and arrows with special symbols</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\autoformat as you type</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12901-5' platform='office2010' modified='2013-02-11'>
      <description>The "Ordinals with superscript" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Proofing\AutoCorrect Options\Ordinals with superscript</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\autoformat as you type</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14745-4' platform='office2010' modified='2013-02-11'>
      <description>The "Fractions with fraction character" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Proofing\AutoCorrect Options\Fractions with fraction character</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\autoformat as you type</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12377-8' platform='office2010' modified='2013-02-11'>
      <description>The "Hyphens with dash" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Proofing\AutoCorrect Options\Hyphens with dash</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\autoformat as you type</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12976-7' platform='office2010' modified='2013-02-11'>
      <description>The "Straight quotes with smart quotes" Visio setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Visio 2010\Visio Options\Proofing\AutoCorrect Options\Straight quotes with smart quotes</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\visio\autoformat as you type</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13652-3' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off auto-switching from horizontal to vertical layout" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Schedule View\Turn off auto-switching from horizontal to vertical layout</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\wunderbar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13048-4' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Legacy Group Calendar migration" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Schedule View\Turn off Legacy Group Calendar migration</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\wunderbar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13290-2' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent My Department Calendar from appearing" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Schedule View\Prevent My Department Calendar from appearing</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\wunderbar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11909-9' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off sharing recommendation" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Schedule View\Turn off sharing recommendation</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12283-8' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent Reporting Line Group Calendar from appearing" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Schedule View\Prevent Reporting Line Group Calendar from appearing</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\wunderbar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12751-4' platform='office2010' modified='2013-02-11'>
      <description>The "Do not allow horizontal calendar view" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Schedule View\Do not allow horizontal calendar view</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\calendar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13595-4' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off auto-switching from vertical to horizontal layout" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Schedule View\Turn off auto-switching from vertical to horizontal layout</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\wunderbar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13177-1' platform='office2010' modified='2013-02-11'>
      <description>The "Prevent Other Department Calendar from appearing" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Calendar Options\Schedule View\Prevent Other Department Calendar from appearing</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\wunderbar</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13504-6' platform='office2010' modified='2013-02-11'>
      <description>The "Maximum number of once-per-day version history items kept" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Versions and Recyle Bin\Maximum number of once-per-day version history items kept</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\versions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13277-9' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Versions and Notebook Recycle Bin in shared notebooks" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Versions and Recyle Bin\Turn off Versions and Notebook Recycle Bin in shared notebooks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\versions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12591-4' platform='office2010' modified='2013-02-11'>
      <description>The "Do not prune versions over time" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Versions and Recyle Bin\Do not prune versions over time</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\versions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12857-9' platform='office2010' modified='2013-02-11'>
      <description>The "Days back to keep items in recycle bin" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Versions and Recyle Bin\Days back to keep items in recycle bin</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\versions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13342-1' platform='office2010' modified='2013-02-11'>
      <description>The "Days of hourly versions not to prune after Days Back" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Versions and Recyle Bin\Days of hourly versions not to prune after Days Back</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\versions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14372-7' platform='office2010' modified='2013-02-11'>
      <description>The "Days back to keep in version history" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Versions and Recyle Bin\Days back to keep in version history</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\versions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14189-5' platform='office2010' modified='2013-02-11'>
      <description>The "Enter text direction for new forms" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath Options\Design\Enter text direction for new forms</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\designer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12381-0' platform='office2010' modified='2013-02-11'>
      <description>The "Email Forms Beaconing UI" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Miscellaneous\Email Forms Beaconing UI</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14012-9' platform='office2010' modified='2013-02-11'>
      <description>The "Allow users to turn on and off printing of background colors." InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Miscellaneous\Allow users to turn on and off printing of background colors.</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\internet explorer\main</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14641-5' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Microsoft InfoPath Filler Control" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Miscellaneous\Disable Microsoft InfoPath Filler Control</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\editor\activexcontrol</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14406-3' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off InfoPath Designer mode" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Miscellaneous\Turn off InfoPath Designer mode</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\designer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13965-9' platform='office2010' modified='2013-02-11'>
      <description>The "Enter URL of location where template parts are stored" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\Miscellaneous\Enter URL of location where template parts are stored</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\designer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12403-2' platform='office2010' modified='2013-02-11'>
      <description>The "Clipart pictures" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\File Locations\Clipart pictures</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13181-3' platform='office2010' modified='2013-02-11'>
      <description>The "Tools" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\File Locations\Tools</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13598-8' platform='office2010' modified='2013-02-11'>
      <description>The "AutoRecover files" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\File Locations\AutoRecover files</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12294-5' platform='office2010' modified='2013-02-11'>
      <description>The "Startup" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\File Locations\Startup</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11816-6' platform='office2010' modified='2013-02-11'>
      <description>The "Default File Location" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Word Options\Advanced\File Locations\Default File Location</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12225-9' platform='office2010' modified='2013-02-11'>
      <description>The "Block opening of pre-release versions of file formats new to Word 2010 through the Compatibility Pack for Office 2010 and Word 2010 Open XML/Word 97-2003 Format Converter" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Office 2010 Converters\Block opening of pre-release versions of file formats new to Word 2010 through the Compatibility Pack for Office 2010 and Word 2010 Open XML/Word 97-2003 Format Converter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14865-0' platform='office2010' modified='2013-02-11'>
      <description>The "Block opening of pre-release versions of file formats new to Excel 2010 through the Compatibility Pack for Office 2010 and Excel 2010 Converter" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Office 2010 Converters\Block opening of pre-release versions of file formats new to Excel 2010 through the Compatibility Pack for Office 2010 and Excel 2010 Converter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14239-8' platform='office2010' modified='2013-02-11'>
      <description>The "Block opening of pre-release versions of file formats new to PowerPoint 2010 through the Compatibility Pack for Office 2010 and PowerPoint 2010 Converter" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Office 2010 Converters\Block opening of pre-release versions of file formats new to PowerPoint 2010 through the Compatibility Pack for Office 2010 and PowerPoint 2010 Converter</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\fileblock</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11655-8' platform='office2010' modified='2013-02-11'>
      <description>The "Add file extensions to block as Level 1" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Security Form Settings\Attachment Security\Add file extensions to block as Level 1</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11682-2' platform='office2010' modified='2013-02-11'>
      <description>The "Display OLE package objects" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Security Form Settings\Attachment Security\Display OLE package objects</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14037-6' platform='office2010' modified='2013-02-11'>
      <description>The "Add file extensions to block as Level 2" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Security Form Settings\Attachment Security\Add file extensions to block as Level 2</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13450-2' platform='office2010' modified='2013-02-11'>
      <description>The "Do not prompt about Level 1 attachments when sending an item" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Security Form Settings\Attachment Security\Do not prompt about Level 1 attachments when sending an item</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13559-0' platform='office2010' modified='2013-02-11'>
      <description>The "Allow users to demote attachments to Level 2" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Security Form Settings\Attachment Security\Allow users to demote attachments to Level 2</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13004-7' platform='office2010' modified='2013-02-11'>
      <description>The "Remove file extensions blocked as Level 2" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Security Form Settings\Attachment Security\Remove file extensions blocked as Level 2</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12197-0' platform='office2010' modified='2013-02-11'>
      <description>The "Do not prompt about Level 1 attachments when closing an item" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Security Form Settings\Attachment Security\Do not prompt about Level 1 attachments when closing an item</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13121-9' platform='office2010' modified='2013-02-11'>
      <description>The "Remove file extensions blocked as Level 1" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Security Form Settings\Attachment Security\Remove file extensions blocked as Level 1</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14802-3' platform='office2010' modified='2013-02-11'>
      <description>The "Display Level 1 attachments" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Security\Security Form Settings\Attachment Security\Display Level 1 attachments</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13103-7' platform='office2010' modified='2013-02-11'>
      <description>The "Display Developer tab in the Ribbon" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Customize Ribbon\Display Developer tab in the Ribbon</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13458-5' platform='office2010' modified='2013-02-11'>
      <description>The "Match minus, dash, cho" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath Options\East Asian Language Find\Match minus, dash, cho</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\fe</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13333-0' platform='office2010' modified='2013-02-11'>
      <description>The "Set EA line breaking" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath Options\East Asian Language Find\Set EA line breaking</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\designer\fe</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12247-3' platform='office2010' modified='2013-02-11'>
      <description>The "Match full/half width forms" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath Options\East Asian Language Find\Match full/half width forms</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\fe</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13776-0' platform='office2010' modified='2013-02-11'>
      <description>The "Match cho-on used for vowels" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath Options\East Asian Language Find\Match cho-on used for vowels</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\fe</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12087-3' platform='office2010' modified='2013-02-11'>
      <description>The "Check if Office is the default editor for Web pages created in Office" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Tools | Options | General | Web Options...\Files\Check if Office is the default editor for Web pages created in Office</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11507-1' platform='office2010' modified='2013-02-11'>
      <description>The "Organize supporting files in a folder" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Tools | Options | General | Web Options...\Files\Organize supporting files in a folder</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12053-5' platform='office2010' modified='2013-02-11'>
      <description>The "Open Office document directly in Office application" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Tools | Options | General | Web Options...\Files\Open Office document directly in Office application</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14832-0' platform='office2010' modified='2013-02-11'>
      <description>The "Open Office documents as read/write while browsing" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Tools | Options | General | Web Options...\Files\Open Office documents as read/write while browsing</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14750-4' platform='office2010' modified='2013-02-11'>
      <description>The "Prompt user to setup printer" Publisher setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Publisher 2010\Miscellaneous\Prompt user to setup printer</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\publisher\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13825-5' platform='office2010' modified='2013-02-11'>
      <description>The "Add double quotes in Hebrew alphabet numbering" Publisher setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Publisher 2010\Miscellaneous\Add double quotes in Hebrew alphabet numbering</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\publisher\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14682-9' platform='office2010' modified='2013-02-11'>
      <description>The "Navigation bar appears on the right" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Display\Navigation bar appears on the right</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\other</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12658-1' platform='office2010' modified='2013-02-11'>
      <description>The "Show Note Containers" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Display\Show Note Containers</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\other</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14320-6' platform='office2010' modified='2013-02-11'>
      <description>The "Page tabs appear on the left" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Display\Page tabs appear on the left</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\other</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14446-9' platform='office2010' modified='2013-02-11'>
      <description>The "Vertical scroll bar appears on left" OneNote setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft OneNote 2010\OneNote Options\Display\Vertical scroll bar appears on left</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\onenote\options\other</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12348-9' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Trusted Documents on the network" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Turn off Trusted Documents on the network</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted documents</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13123-5' platform='office2010' modified='2013-02-11'>
      <description>The "VBA Macro Notification Settings" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\VBA Macro Notification Settings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12451-1' platform='office2010' modified='2013-02-11'>
      <description>The "Set maximum number of trust records to preserve" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Set maximum number of trust records to preserve</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted documents</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12525-2' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Trust Bar Notification for unsigned application add-ins and block them" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Disable Trust Bar Notification for unsigned application add-ins and block them</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12203-6' platform='office2010' modified='2013-02-11'>
      <description>The "Require that application add-ins are signed by Trusted Publisher" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Require that application add-ins are signed by Trusted Publisher</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11735-8' platform='office2010' modified='2013-02-11'>
      <description>The "Trust access to Visual Basic Project" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Trust access to Visual Basic Project</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12254-9' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Data Execution Prevention" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Turn off Data Execution Prevention</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14790-0' platform='office2010' modified='2013-02-11'>
      <description>The "Disable all application add-ins" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Disable all application add-ins</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12874-4' platform='office2010' modified='2013-02-11'>
      <description>The "Set maximum number of trusted documents" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Set maximum number of trusted documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted documents</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14612-6' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off trusted documents" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\PowerPoint Options\Security\Trust Center\Turn off trusted documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\security\trusted documents</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12028-7' platform='office2010' modified='2013-02-11'>
      <description>The "Change or delete link to the proofing tools download site" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Display Language\Change or delete link to the proofing tools download site</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13151-6' platform='office2010' modified='2013-02-11'>
      <description>The "Display help in" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Display Language\Display help in</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12138-4' platform='office2010' modified='2013-02-11'>
      <description>The "Change or delete link to language pack download site" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Display Language\Change or delete link to language pack download site</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11776-2' platform='office2010' modified='2013-02-11'>
      <description>The "Display menus and dialog boxes in" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Display Language\Display menus and dialog boxes in</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12985-8' platform='office2010' modified='2013-02-11'>
      <description>The "Configure form regions permissions" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Form Region Settings\Configure form regions permissions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\addins</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12667-2' platform='office2010' modified='2013-02-11'>
      <description>The "Locked form regions" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Form Region Settings\Locked form regions</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\addins\lockedformregions</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13710-9' platform='office2010' modified='2013-02-11'>
      <description>The "Office.com" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Help\Office.com</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13992-3' platform='office2010' modified='2013-02-11'>
      <description>The "Use online translation dictionaries" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Miscellaneous\Use online translation dictionaries</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\research\translation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13873-5' platform='office2010' modified='2013-02-11'>
      <description>The "Tools | Compare and Merge Documents, Legal blackline" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Miscellaneous\Tools | Compare and Merge Documents, Legal blackline</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13556-6' platform='office2010' modified='2013-02-11'>
      <description>The "Alternate revision bar position in printed document" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Miscellaneous\Alternate revision bar position in printed document</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12125-1' platform='office2010' modified='2013-02-11'>
      <description>The "Disable MRU list in font dropdown" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Miscellaneous\Disable MRU list in font dropdown</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14250-5' platform='office2010' modified='2013-02-11'>
      <description>The "Volume preference" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Miscellaneous\Volume preference</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14423-8' platform='office2010' modified='2013-02-11'>
      <description>The "Do not use online machine translation" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Miscellaneous\Do not use online machine translation</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\research\translation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12538-5' platform='office2010' modified='2013-02-11'>
      <description>The "Set comment fields for Outlook Contacts Dictionary" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\IME (Japanese)\Set comment fields for Outlook Contacts Dictionary</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\imejp\14.0\wswordcomment\plugins\mapi</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13200-1' platform='office2010' modified='2013-02-11'>
      <description>The "Set update interval for Outlook Global Address List Dictionary" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\IME (Japanese)\Set update interval for Outlook Global Address List Dictionary</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\imejp\14.0\wswordcomment\plugins\mapi</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13964-2' platform='office2010' modified='2013-02-11'>
      <description>The "Restrict character code range of conversion" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\IME (Japanese)\Restrict character code range of conversion</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\ime\imejp\14.0\msime</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13850-3' platform='office2010' modified='2013-02-11'>
      <description>The "Set comment fields for Outlook Global Address List Dictionary" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\IME (Japanese)\Set comment fields for Outlook Global Address List Dictionary</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\imejp\14.0\wswordcomment\plugins\mapi</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12854-6' platform='office2010' modified='2013-02-11'>
      <description>The "Set update interval for Outlook Contacts Dictionary" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\IME (Japanese)\Set update interval for Outlook Contacts Dictionary</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\imejp\14.0\wswordcomment\plugins\mapi</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13235-7' platform='office2010' modified='2013-02-11'>
      <description>The "Do not include Non-Publishing Standard Glyph in the candidate list" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\IME (Japanese)\Do not include Non-Publishing Standard Glyph in the candidate list</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\ime\imejp\14.0\msime</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12680-5' platform='office2010' modified='2013-02-11'>
      <description>The "Spanish (Peru)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Spanish (Peru)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13085-6' platform='office2010' modified='2013-02-11'>
      <description>The "Welsh" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Welsh</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13138-3' platform='office2010' modified='2013-02-11'>
      <description>The "Workflow Cache 13" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Workflow Cache\Workflow Cache 13</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\workflow\cache\workflow13</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13932-9' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #20" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Trusted Location #20</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\trusted locations\all applications\location20</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12141-8' platform='office2010' modified='2013-02-11'>
      <description>The "Telugu" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Telugu</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13526-9' platform='office2010' modified='2013-02-11'>
      <description>The "Turkish" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Turkish</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12966-8' platform='office2010' modified='2013-02-11'>
      <description>The "Suppress hyperlink warnings" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Suppress hyperlink warnings</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12437-0' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #1" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Trusted Location #1</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\trusted locations\all applications\location1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12165-7' platform='office2010' modified='2013-02-11'>
      <description>The "Turn Off Office Live Workspace Integration" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Office Live Workspace\Turn Off Office Live Workspace Integration</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\officeliveworkspace</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13532-7' platform='office2010' modified='2013-02-11'>
      <description>The "Tamazight (Arabic, Morocco)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Tamazight (Arabic, Morocco)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13312-4' platform='office2010' modified='2013-02-11'>
      <description>The "Unsafe Location #7" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Protected View\Unsafe Location #7</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\protectedview\locations\location7</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13689-5' platform='office2010' modified='2013-02-11'>
      <description>The "Stop reporting non-critical errors" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Improved Error Reporting\Stop reporting non-critical errors</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\shipasserts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12593-0' platform='office2010' modified='2013-02-11'>
      <description>The "Workflow Cache 2" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Workflow Cache\Workflow Cache 2</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\workflow\cache\workflow3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12019-6' platform='office2010' modified='2013-02-11'>
      <description>The "Workflow Cache 4" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Workflow Cache\Workflow Cache 4</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\workflow\cache\workflow4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12512-0' platform='office2010' modified='2013-02-11'>
      <description>The "Tigrigna (Ethiopia)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Tigrigna (Ethiopia)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13567-3' platform='office2010' modified='2013-02-11'>
      <description>The "Tajik" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Tajik</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14812-2' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #19" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Trusted Location #19</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\trusted locations\all applications\location19</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13983-2' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #11" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Trusted Location #11</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\trusted locations\all applications\location11</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11996-6' platform='office2010' modified='2013-02-11'>
      <description>The "Suppress Office Signing Providers" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Signing\Suppress Office Signing Providers</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\signatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12979-1' platform='office2010' modified='2013-02-11'>
      <description>The "Unsafe Location #8" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Protected View\Unsafe Location #8</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\protectedview\locations\location8</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13743-0' platform='office2010' modified='2013-02-11'>
      <description>The "Ukrainian" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Ukrainian</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14512-8' platform='office2010' modified='2013-02-11'>
      <description>The "Suppress external signature services menu item" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Signing\Suppress external signature services menu item</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\signatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11683-0' platform='office2010' modified='2013-02-11'>
      <description>The "Wolof" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Wolof</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13165-6' platform='office2010' modified='2013-02-11'>
      <description>The "Unsafe Location #13" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Protected View\Unsafe Location #13</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\protectedview\locations\location13</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12320-8' platform='office2010' modified='2013-02-11'>
      <description>The "Sutu (South Africa)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Sutu (South Africa)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12275-4' platform='office2010' modified='2013-02-11'>
      <description>The "Spanish (Spain)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Spanish (Spain)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12805-8' platform='office2010' modified='2013-02-11'>
      <description>The "Unsafe Location #2" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Protected View\Unsafe Location #2</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\protectedview\locations\location2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11760-6' platform='office2010' modified='2013-02-11'>
      <description>The "Use Office 2003 New Document dialog box" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Use Office 2003 New Document dialog box</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12872-8' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #5" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Trusted Location #5</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\trusted locations\all applications\location5</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14338-8' platform='office2010' modified='2013-02-11'>
      <description>The "URL for location of document templates displayed when applications do not recognize rights-managed documents" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Manage Restricted Permissions\URL for location of document templates displayed when applications do not recognize rights-managed documents</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\drm</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12978-3' platform='office2010' modified='2013-02-11'>
      <description>The "Unsafe Location #12" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Protected View\Unsafe Location #12</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\protectedview\locations\location12</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12601-1' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #16" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Trusted Location #16</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\trusted locations\all applications\location16</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13558-2' platform='office2010' modified='2013-02-11'>
      <description>The "Workgroup building blocks path" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Shared paths\Workgroup building blocks path</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13254-8' platform='office2010' modified='2013-02-11'>
      <description>The "Vietnamese" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Vietnamese</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11931-3' platform='office2010' modified='2013-02-11'>
      <description>The "Workflow Cache 1" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Workflow Cache\Workflow Cache 1</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\workflow\cache\workflow1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12382-8' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #6" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Trusted Location #6</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\trusted locations\all applications\location6</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12626-8' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #14" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Trusted Location #14</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\trusted locations\all applications\location14</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12206-9' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #13" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Trusted Location #13</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\trusted locations\all applications\location13</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12941-1' platform='office2010' modified='2013-02-11'>
      <description>The "With a Web discussions link" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Collaboration Settings\Default message text for a reply...\With a Web discussions link</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\reviewcycle</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13418-9' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #15" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Trusted Location #15</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\trusted locations\all applications\location15</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14451-9' platform='office2010' modified='2013-02-11'>
      <description>The "Turkmen" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Turkmen</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13661-4' platform='office2010' modified='2013-02-11'>
      <description>The "Unsafe Location #6" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Protected View\Unsafe Location #6</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\protectedview\locations\location6</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13314-0' platform='office2010' modified='2013-02-11'>
      <description>The "Swedish (Sweden)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Swedish (Sweden)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13670-5' platform='office2010' modified='2013-02-11'>
      <description>The "Unsafe Location #20" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Protected View\Unsafe Location #20</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\protectedview\locations\location20</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12851-2' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off presence integration" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Turn off presence integration</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\im</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14736-3' platform='office2010' modified='2013-02-11'>
      <description>The "Workflow Cache 8" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Workflow Cache\Workflow Cache 8</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\workflow\cache\workflow8</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12023-8' platform='office2010' modified='2013-02-11'>
      <description>The "Unsafe Location #15" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Protected View\Unsafe Location #15</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\protectedview\locations\location15</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12175-6' platform='office2010' modified='2013-02-11'>
      <description>The "Upper Sorbian" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Upper Sorbian</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13398-3' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off click to telephone" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Turn off click to telephone</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\im</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12738-1' platform='office2010' modified='2013-02-11'>
      <description>The "Spanish (Puerto Rico)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Spanish (Puerto Rico)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14175-4' platform='office2010' modified='2013-02-11'>
      <description>The "Spanish (United States)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Spanish (United States)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11895-0' platform='office2010' modified='2013-02-11'>
      <description>The "Update links on save" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Tools | Options | General | Web Options...\Files\Update links on save</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12802-5' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #8" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Trusted Location #8</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\trusted locations\all applications\location8</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14607-6' platform='office2010' modified='2013-02-11'>
      <description>The "Workflow Cache 5" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Workflow Cache\Workflow Cache 5</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\workflow\cache\workflow5</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12478-4' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Local Solution" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Document Information Panel\Trust Local Solution</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\documentinformationpanel\trustsolution</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13216-7' platform='office2010' modified='2013-02-11'>
      <description>The "Unsafe Location #10" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Protected View\Unsafe Location #10</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\protectedview\locations\location10</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13947-7' platform='office2010' modified='2013-02-11'>
      <description>The "With a link and an attachment" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Collaboration Settings\Default message text for a review request...\With a link and an attachment</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\reviewcycle</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13076-5' platform='office2010' modified='2013-02-11'>
      <description>The "Swahili" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Swahili</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12564-1' platform='office2010' modified='2013-02-11'>
      <description>The "Workflow Cache 6" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Workflow Cache\Workflow Cache 6</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\workflow\cache\workflow6</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13506-1' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off PDF encryption setting UI" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Turn off PDF encryption setting UI</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\fixedformat</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13229-0' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Information Rights Management user interface" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Manage Restricted Permissions\Turn off Information Rights Management user interface</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\drm</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13011-2' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #9" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Trusted Location #9</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\trusted locations\all applications\location9</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13224-1' platform='office2010' modified='2013-02-11'>
      <description>The "Tatar" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Tatar</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12316-6' platform='office2010' modified='2013-02-11'>
      <description>The "Thai" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Thai</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14780-1' platform='office2010' modified='2013-02-11'>
      <description>The "Target monitor" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Tools | Options | General | Web Options...\Browsers\Target monitor</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11696-2' platform='office2010' modified='2013-02-11'>
      <description>The "Uyghur (PRC)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Uyghur (PRC)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13096-3' platform='office2010' modified='2013-02-11'>
      <description>The "Specify Permission Policy Path" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Manage Restricted Permissions\Specify Permission Policy Path</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\drm</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13274-6' platform='office2010' modified='2013-02-11'>
      <description>The "With a Web discussions link and an attachment" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Collaboration Settings\Default message text for a review request...\With a Web discussions link and an attachment</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\reviewcycle</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12687-0' platform='office2010' modified='2013-02-11'>
      <description>The "With just a simple Web discussions link" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Collaboration Settings\Default message text for a reply...\With just a simple Web discussions link</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\reviewcycle</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12781-1' platform='office2010' modified='2013-02-11'>
      <description>The "Web Folders: Managing pairs of Web pages and folders" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Web Folders: Managing pairs of Web pages and folders</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\windows\currentversion\explorer</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14464-2' platform='office2010' modified='2013-02-11'>
      <description>The "Unsafe Location #18" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Protected View\Unsafe Location #18</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\protectedview\locations\location18</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13442-9' platform='office2010' modified='2013-02-11'>
      <description>The "Use long file names whenever possible" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Tools | Options | General | Web Options...\Files\Use long file names whenever possible</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13320-7' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #17" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Trusted Location #17</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\trusted locations\all applications\location17</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13008-8' platform='office2010' modified='2013-02-11'>
      <description>The "Spanish (Panama)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Spanish (Panama)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12223-4' platform='office2010' modified='2013-02-11'>
      <description>The "Workflow Cache 12" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Workflow Cache\Workflow Cache 12</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\workflow\cache\workflow12</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12174-9' platform='office2010' modified='2013-02-11'>
      <description>The "Workgroup templates path" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Shared paths\Workgroup templates path</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14031-9' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Open Extended Dictionary" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\IME (Japanese)\Turn off Open Extended Dictionary</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\ime\shared\14.0\openextendeddict</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14243-0' platform='office2010' modified='2013-02-11'>
      <description>The "With a simple Web discussions link and an attachment" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Collaboration Settings\Default message text for a review request...\With a simple Web discussions link and an attachment</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\reviewcycle</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13529-3' platform='office2010' modified='2013-02-11'>
      <description>The "Workflow Cache 9" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Workflow Cache\Workflow Cache 9</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\workflow\cache\workflow9</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14557-3' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off error reporting for files that fail file validation" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Turn off error reporting for files that fail file validation</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\filevalidation</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12570-8' platform='office2010' modified='2013-02-11'>
      <description>The "Suggest from main dictionary only" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Tools | Options | Spelling\Suggest from main dictionary only</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\shared tools\proofing tools\1.0\office</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13022-9' platform='office2010' modified='2013-02-11'>
      <description>The "Tamil" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Tamil</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12189-7' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Internet search integration" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\IME (Japanese)\Turn off Internet search integration</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\ime\shared\14.0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14330-5' platform='office2010' modified='2013-02-11'>
      <description>The "Spanish (Venezuela)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Spanish (Venezuela)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12773-8' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off predictive input" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\IME (Japanese)\Turn off predictive input</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\ime\imejp\14.0\msime</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14401-4' platform='office2010' modified='2013-02-11'>
      <description>The "Workflow Cache 14" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Workflow Cache\Workflow Cache 14</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\workflow\cache\workflow14</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14392-5' platform='office2010' modified='2013-02-11'>
      <description>The "Specify timestamp server name" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Specify timestamp server name</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\signatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13986-5' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off click to IM option" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Contact Card\Turn off click to IM option</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\im</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13838-8' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off SharePoint dictionary" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\IME (Japanese)\Turn off SharePoint dictionary</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\ime\shared\14.0\sharepointdict</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11956-0' platform='office2010' modified='2013-02-11'>
      <description>The "Unsafe Location #11" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Protected View\Unsafe Location #11</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\protectedview\locations\location11</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13348-8' platform='office2010' modified='2013-02-11'>
      <description>The "Specify minimum XAdES level for digital signature generation" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Specify minimum XAdES level for digital signature generation</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\signatures</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12095-6' platform='office2010' modified='2013-02-11'>
      <description>The "Unsafe Location #9" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Protected View\Unsafe Location #9</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\protectedview\locations\location9</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12391-9' platform='office2010' modified='2013-02-11'>
      <description>The "When choosing 'Send for Review...'" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Collaboration Settings\When choosing 'Send for Review...'</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13997-2' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #18" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Trusted Location #18</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\trusted locations\all applications\location18</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12893-4' platform='office2010' modified='2013-02-11'>
      <description>The "Workflow Cache 7" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Workflow Cache\Workflow Cache 7</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\workflow\cache\workflow7</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13895-8' platform='office2010' modified='2013-02-11'>
      <description>The "Tsonga" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Tsonga</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13626-7' platform='office2010' modified='2013-02-11'>
      <description>The "Workflow Cache 11" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Workflow Cache\Workflow Cache 11</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\workflow\cache\workflow11</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13715-8' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #10" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Trusted Location #10</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\trusted locations\all applications\location10</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11565-9' platform='office2010' modified='2013-02-11'>
      <description>The "Unsafe Location #1" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Protected View\Unsafe Location #1</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\protectedview\locations\location1</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13036-9' platform='office2010' modified='2013-02-11'>
      <description>The "Turn on file synchronization via SOAP over HTTP" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Server Settings\Turn on file synchronization via SOAP over HTTP</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12905-6' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #4" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Trusted Location #4</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\trusted locations\all applications\location4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14836-1' platform='office2010' modified='2013-02-11'>
      <description>The "Yoruba" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Yoruba</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14797-5' platform='office2010' modified='2013-02-11'>
      <description>The "Suppress recommended settings dialog" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Suppress recommended settings dialog</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12610-2' platform='office2010' modified='2013-02-11'>
      <description>The "Venda" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Venda</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14373-5' platform='office2010' modified='2013-02-11'>
      <description>The "Syriac" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Syriac</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14483-2' platform='office2010' modified='2013-02-11'>
      <description>The "Web Archive encoding" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Web Archives\Web Archive encoding</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12950-2' platform='office2010' modified='2013-02-11'>
      <description>The "Use auto-change list" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Tools | Options | Spelling\Use auto-change list</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\options\vpref</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13099-7' platform='office2010' modified='2013-02-11'>
      <description>The "Turn on misconversion logging for misconversion report" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\IME (Japanese)\Turn on misconversion logging for misconversion report</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\ime\shared\14.0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12821-5' platform='office2010' modified='2013-02-11'>
      <description>The "Uzbek (Latin)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Uzbek (Latin)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14110-1' platform='office2010' modified='2013-02-11'>
      <description>The "User queries path" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Shared paths\User queries path</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12899-1' platform='office2010' modified='2013-02-11'>
      <description>The "Web Query dialog box home page" Excel setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Shared paths\Web Query dialog box home page</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\excel\options</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13730-7' platform='office2010' modified='2013-02-11'>
      <description>The "Use ClearType" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Global Options\Use ClearType</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14482-4' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off custom dictionary" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\IME (Japanese)\Turn off custom dictionary</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\ime\shared\14.0</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11805-9' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #3" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Trusted Location #3</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\trusted locations\all applications\location3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13453-6' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off saving input history data for predictive input to file" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\IME (Japanese)\Turn off saving input history data for predictive input to file</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\ime\imejp\14.0\msime</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14657-1' platform='office2010' modified='2013-02-11'>
      <description>The "Swedish (Finland)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Swedish (Finland)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13593-9' platform='office2010' modified='2013-02-11'>
      <description>The "User templates path" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Shared paths\User templates path</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12607-8' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off screen clipping" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Disable Items in User Interface\Turn off screen clipping</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\insert media\screenshot</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11926-3' platform='office2010' modified='2013-02-11'>
      <description>The "Tigrigna (Eritrea)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Tigrigna (Eritrea)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14038-4' platform='office2010' modified='2013-02-11'>
      <description>The "Tibetan (PRC)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Tibetan (PRC)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14327-1' platform='office2010' modified='2013-02-11'>
      <description>The "Spanish (Nicaragua)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Spanish (Nicaragua)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14487-3' platform='office2010' modified='2013-02-11'>
      <description>The "With a Web discussions link" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Collaboration Settings\Default message text for a review request...\With a Web discussions link</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\reviewcycle</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13376-9' platform='office2010' modified='2013-02-11'>
      <description>The "Urdu" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Urdu</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13758-8' platform='office2010' modified='2013-02-11'>
      <description>The "Stop reporting error messages" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Improved Error Reporting\Stop reporting error messages</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\alerts</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14380-0' platform='office2010' modified='2013-02-11'>
      <description>The "Tamazight (Latin, Algeria)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Tamazight (Latin, Algeria)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12357-0' platform='office2010' modified='2013-02-11'>
      <description>The "Spanish (Paraguay)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Spanish (Paraguay)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14342-0' platform='office2010' modified='2013-02-11'>
      <description>The "Yi (PRC)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Yi (PRC)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12969-2' platform='office2010' modified='2013-02-11'>
      <description>The "Use system font instead of the Office default UI font" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Use system font instead of the Office default UI font</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\general</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12031-1' platform='office2010' modified='2013-02-11'>
      <description>The "Tooltip for disabled toolbar buttons and menu items" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Disable Items in User Interface\Tooltip for disabled toolbar buttons and menu items</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\toolbars</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13194-6' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #2" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Trusted Location #2</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\trusted locations\all applications\location2</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14528-4' platform='office2010' modified='2013-02-11'>
      <description>The "Workflow Cache 15" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Workflow Cache\Workflow Cache 15</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\workflow\cache\workflow15</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14046-7' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #12" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Trusted Location #12</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\trusted locations\all applications\location12</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12491-7' platform='office2010' modified='2013-02-11'>
      <description>The "With a simple Web discussions link" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Collaboration Settings\Default message text for a reply...\With a simple Web discussions link</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\reviewcycle</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11886-9' platform='office2010' modified='2013-02-11'>
      <description>The "Yiddish" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Yiddish</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14258-8' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off user customizations via UI" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Global Options\Customize\Turn off user customizations via UI</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\toolbars\outlook</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13101-1' platform='office2010' modified='2013-02-11'>
      <description>The "Unsafe Location #3" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Protected View\Unsafe Location #3</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\protectedview\locations\location3</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13578-0' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off all user customizations" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Global Options\Customize\Turn off all user customizations</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\toolbars\onenote</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12236-6' platform='office2010' modified='2013-02-11'>
      <description>The "Trust Center: Trusted Location #7" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Trusted Location #7</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\trusted locations\all applications\location7</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14310-7' platform='office2010' modified='2013-02-11'>
      <description>The "Unsafe Location #16" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Protected View\Unsafe Location #16</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\protectedview\locations\location16</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12599-7' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off Outlook name dictionaries" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\IME (Japanese)\Turn off Outlook name dictionaries</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\ime\shared\14.0\mapi</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11792-9' platform='office2010' modified='2013-02-11'>
      <description>The "Turn off saving auto-tuning data to file" setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\IME (Japanese)\Turn off saving auto-tuning data to file</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\ime\imejp\14.0\msime</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12542-7' platform='office2010' modified='2013-02-11'>
      <description>The "With just an attachment" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Collaboration Settings\Default message text for a reply...\With just an attachment</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\reviewcycle</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14196-0' platform='office2010' modified='2013-02-11'>
      <description>The "Spanish (Uruguay)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Spanish (Uruguay)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14319-8' platform='office2010' modified='2013-02-11'>
      <description>The "Unsafe Location #5" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Protected View\Unsafe Location #5</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\protectedview\locations\location5</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13154-0' platform='office2010' modified='2013-02-11'>
      <description>The "Unsafe Location #19" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Protected View\Unsafe Location #19</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\protectedview\locations\location19</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13141-7' platform='office2010' modified='2013-02-11'>
      <description>The "Unsafe Location #14" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Protected View\Unsafe Location #14</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\protectedview\locations\location14</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12859-5' platform='office2010' modified='2013-02-11'>
      <description>The "With a simple Web discussions link" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Collaboration Settings\Default message text for a review request...\With a simple Web discussions link</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\reviewcycle</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14014-5' platform='office2010' modified='2013-02-11'>
      <description>The "Unsafe Location #4" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Protected View\Unsafe Location #4</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\protectedview\locations\location4</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14983-1' platform='office2010' modified='2013-02-11'>
      <description>The "Uzbek (Cyrillic)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Uzbek (Cyrillic)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14337-0' platform='office2010' modified='2013-02-11'>
      <description>The "Unsafe Location #17" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Security Settings\Trust Center\Protected View\Unsafe Location #17</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\security\protectedview\locations\location17</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12505-4' platform='office2010' modified='2013-02-11'>
      <description>The "Yakut" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Yakut</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13285-2' platform='office2010' modified='2013-02-11'>
      <description>The "Workflow Cache 10" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Miscellaneous\Workflow Cache\Workflow Cache 10</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\common\workflow\cache\workflow10</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12050-1' platform='office2010' modified='2013-02-11'>
      <description>The "Do not record listed Outlook items in Journal" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Journal Options\Do not record listed Outlook items in Journal</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\shared tools\outlook\journaling\e-mail message</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13147-4' platform='office2010' modified='2013-02-11'>
      <description>The "Automatically journal these items" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Journal Options\Automatically journal these items</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\shared tools\outlook\journaling\task request</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14730-6' platform='office2010' modified='2013-02-11'>
      <description>The "Journal entry options" Outlook setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Outlook 2010\Outlook Options\Preferences\Journal Options\Journal entry options</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\outlook\options\journal</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12110-3' platform='office2010' modified='2013-02-11'>
      <description>The "Hide missing component download hyperlinks" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft SharePoint Designer 2010\Downloading Framework Components\Hide missing component download hyperlinks</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14547-4' platform='office2010' modified='2013-02-11'>
      <description>The "Set download location for Microsoft .NET Framework 3.5 SP1" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft SharePoint Designer 2010\Downloading Framework Components\Set download location for Microsoft .NET Framework 3.5 SP1</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12156-6' platform='office2010' modified='2013-02-11'>
      <description>The "Enable AutoRecover" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath Options\Advanced\Enable AutoRecover</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14808-0' platform='office2010' modified='2013-02-11'>
      <description>The "AutoRecover Interval" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath Options\Advanced\AutoRecover Interval</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14357-8' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Common Language Runtime errors when filling out forms" InfoPath setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft InfoPath 2010\InfoPath Options\Advanced\Disable Common Language Runtime errors when filling out forms</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\infopath\form debugging</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14105-1' platform='office2010' modified='2013-02-11'>
      <description>The "Online content options" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Tools | Options | General | Service Options...\Online Content\Online content options</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\internet</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12113-7' platform='office2010' modified='2013-02-11'>
      <description>The "Show the New template gallery when starting Publisher" Publisher setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Publisher 2010\Publisher Options\General\Show the New template gallery when starting Publisher</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\publisher\preferences</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13219-1' platform='office2010' modified='2013-02-11'>
      <description>The "Disable Slide Update" PowerPoint setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft PowerPoint 2010\Miscellaneous\Disable Slide Update</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\powerpoint\slide libraries</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12964-3' platform='office2010' modified='2013-02-11'>
      <description>The "Disable commands" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Disable Items in User Interface\Predefined\Disable commands</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\disabledcmdbaritemscheckboxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12776-1' platform='office2010' modified='2013-02-11'>
      <description>The "Disable shortcut keys" Word setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Word 2010\Disable Items in User Interface\Predefined\Disable shortcut keys</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\word\disabledshortcutkeyscheckboxes</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13114-4' platform='office2010' modified='2013-02-11'>
      <description>The "Disable commands" Publisher setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Publisher 2010\Disable Items in User Interface\Custom\Disable commands</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\publisher\disabledcmdbaritemslist</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12303-4' platform='office2010' modified='2013-02-11'>
      <description>The "Afrikaans" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Afrikaans</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12760-5' platform='office2010' modified='2013-02-11'>
      <description>The "Greek" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Greek</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12624-3' platform='office2010' modified='2013-02-11'>
      <description>The "Maori" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Maori</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13292-8' platform='office2010' modified='2013-02-11'>
      <description>The "Amharic" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Amharic</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12140-0' platform='office2010' modified='2013-02-11'>
      <description>The "Alsatian" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Alsatian</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12430-5' platform='office2010' modified='2013-02-11'>
      <description>The "Assamese (India)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Assamese (India)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14662-1' platform='office2010' modified='2013-02-11'>
      <description>The "Russian (Moldova)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Russian (Moldova)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12323-2' platform='office2010' modified='2013-02-11'>
      <description>The "Bengali (Bangladesh)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Bengali (Bangladesh)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13419-7' platform='office2010' modified='2013-02-11'>
      <description>The "Romanian (Moldova)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Romanian (Moldova)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12195-4' platform='office2010' modified='2013-02-11'>
      <description>The "Gaelic (United Kingdom)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Gaelic (United Kingdom)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14605-0' platform='office2010' modified='2013-02-11'>
      <description>The "Kazakh" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Kazakh</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13038-5' platform='office2010' modified='2013-02-11'>
      <description>The "Chinese (Hong Kong S.A.R.)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Chinese (Hong Kong S.A.R.)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13457-7' platform='office2010' modified='2013-02-11'>
      <description>The "Spanish (El Salvador)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Spanish (El Salvador)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13250-6' platform='office2010' modified='2013-02-11'>
      <description>The "Armenian (Armenia)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Armenian (Armenia)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14602-7' platform='office2010' modified='2013-02-11'>
      <description>The "Inuktitut (Latin)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Inuktitut (Latin)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12310-9' platform='office2010' modified='2013-02-11'>
      <description>The "Korean" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Korean</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12349-7' platform='office2010' modified='2013-02-11'>
      <description>The "Serbian (Latin, Serbia and Montenegro (Former))" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Serbian (Latin, Serbia and Montenegro (Former))</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11993-3' platform='office2010' modified='2013-02-11'>
      <description>The "Georgian" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Georgian</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12490-9' platform='office2010' modified='2013-02-11'>
      <description>The "Serbian (Latin, Serbia)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Serbian (Latin, Serbia)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12355-4' platform='office2010' modified='2013-02-11'>
      <description>The "Quechua (Bolivia)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Quechua (Bolivia)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12216-8' platform='office2010' modified='2013-02-11'>
      <description>The "Igbo" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Igbo</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12809-0' platform='office2010' modified='2013-02-11'>
      <description>The "Sami, Southern (Sweden)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Sami, Southern (Sweden)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13330-6' platform='office2010' modified='2013-02-11'>
      <description>The "Romanian (Romania)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Romanian (Romania)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14260-4' platform='office2010' modified='2013-02-11'>
      <description>The "Spanish (Guatemala)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Spanish (Guatemala)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12942-9' platform='office2010' modified='2013-02-11'>
      <description>The "Papiamentu" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Papiamentu</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14187-9' platform='office2010' modified='2013-02-11'>
      <description>The "Fulfulde" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Fulfulde</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13849-5' platform='office2010' modified='2013-02-11'>
      <description>The "Hawaiian" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Hawaiian</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12883-5' platform='office2010' modified='2013-02-11'>
      <description>The "Arabic (Yemen)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Arabic (Yemen)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14426-1' platform='office2010' modified='2013-02-11'>
      <description>The "Setswana" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Setswana</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13701-8' platform='office2010' modified='2013-02-11'>
      <description>The "Mongolian (Traditional Mongolian)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Mongolian (Traditional Mongolian)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12396-8' platform='office2010' modified='2013-02-11'>
      <description>The "Sami, Skolt (Finland)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Sami, Skolt (Finland)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14168-9' platform='office2010' modified='2013-02-11'>
      <description>The "English (Belize)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\English (Belize)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12588-0' platform='office2010' modified='2013-02-11'>
      <description>The "Serbian (Latin, Montenegro)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Serbian (Latin, Montenegro)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11586-5' platform='office2010' modified='2013-02-11'>
      <description>The "Arabic (Algeria)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Arabic (Algeria)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13681-2' platform='office2010' modified='2013-02-11'>
      <description>The "Spanish (Honduras)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Spanish (Honduras)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12734-0' platform='office2010' modified='2013-02-11'>
      <description>The "Lithuanian" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Lithuanian</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12199-6' platform='office2010' modified='2013-02-11'>
      <description>The "Bosnian (Cyrillic, Bosnia and Herzegovina)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Bosnian (Cyrillic, Bosnia and Herzegovina)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13604-4' platform='office2010' modified='2013-02-11'>
      <description>The "Macedonian (FYROM)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Macedonian (FYROM)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13369-4' platform='office2010' modified='2013-02-11'>
      <description>The "Azeri (Latin)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Azeri (Latin)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12550-0' platform='office2010' modified='2013-02-11'>
      <description>The "Konkani" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Konkani</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13792-7' platform='office2010' modified='2013-02-11'>
      <description>The "French (Haiti)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\French (Haiti)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13762-0' platform='office2010' modified='2013-02-11'>
      <description>The "Hungarian" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Hungarian</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12770-4' platform='office2010' modified='2013-02-11'>
      <description>The "Sindhi (Devanagari)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Sindhi (Devanagari)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14245-5' platform='office2010' modified='2013-02-11'>
      <description>The "Dutch (Netherlands)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Dutch (Netherlands)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12445-3' platform='office2010' modified='2013-02-11'>
      <description>The "Inuktitut (Syllabics)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Inuktitut (Syllabics)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14275-2' platform='office2010' modified='2013-02-11'>
      <description>The "Oriya" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Oriya</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13239-9' platform='office2010' modified='2013-02-11'>
      <description>The "French (Cameroon)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\French (Cameroon)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13773-7' platform='office2010' modified='2013-02-11'>
      <description>The "Sinhala" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Sinhala</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13207-6' platform='office2010' modified='2013-02-11'>
      <description>The "Quechua (Ecuador)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Quechua (Ecuador)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14742-1' platform='office2010' modified='2013-02-11'>
      <description>The "Mongolian (Cyrillic)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Mongolian (Cyrillic)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13770-3' platform='office2010' modified='2013-02-11'>
      <description>The "Croatian (Bosnia and Herzegovina)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Croatian (Bosnia and Herzegovina)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13166-4' platform='office2010' modified='2013-02-11'>
      <description>The "English (Hong Kong S.A.R.)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\English (Hong Kong S.A.R.)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13861-0' platform='office2010' modified='2013-02-11'>
      <description>The "Danish" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Danish</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12361-2' platform='office2010' modified='2013-02-11'>
      <description>The "English (Ireland)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\English (Ireland)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13315-7' platform='office2010' modified='2013-02-11'>
      <description>The "French (Monaco)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\French (Monaco)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11897-6' platform='office2010' modified='2013-02-11'>
      <description>The "Azeri (Cyrillic)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Azeri (Cyrillic)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13623-4' platform='office2010' modified='2013-02-11'>
      <description>The "Chinese (Singapore)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Chinese (Singapore)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12523-7' platform='office2010' modified='2013-02-11'>
      <description>The "Spanish (Dominican Republic)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Spanish (Dominican Republic)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12317-4' platform='office2010' modified='2013-02-11'>
      <description>The "Spanish (Argentina)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Spanish (Argentina)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13056-7' platform='office2010' modified='2013-02-11'>
      <description>The "Kannada" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Kannada</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12742-3' platform='office2010' modified='2013-02-11'>
      <description>The "Catalan" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Catalan</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12727-4' platform='office2010' modified='2013-02-11'>
      <description>The "Arabic (Egypt)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Arabic (Egypt)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12615-1' platform='office2010' modified='2013-02-11'>
      <description>The "Slovak" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Slovak</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13684-6' platform='office2010' modified='2013-02-11'>
      <description>The "Portuguese (Brazil)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Portuguese (Brazil)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12574-0' platform='office2010' modified='2013-02-11'>
      <description>The "Kashmiri (Devanagari)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Kashmiri (Devanagari)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14137-4' platform='office2010' modified='2013-02-11'>
      <description>The "Chinese (PRC)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Chinese (PRC)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12735-7' platform='office2010' modified='2013-02-11'>
      <description>The "Finnish" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Finnish</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13501-2' platform='office2010' modified='2013-02-11'>
      <description>The "Kanuri" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Kanuri</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11924-8' platform='office2010' modified='2013-02-11'>
      <description>The "French (Canada)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\French (Canada)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12695-3' platform='office2010' modified='2013-02-11'>
      <description>The "Maltese" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Maltese</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12409-9' platform='office2010' modified='2013-02-11'>
      <description>The "Arabic (Saudi Arabia)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Arabic (Saudi Arabia)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12515-3' platform='office2010' modified='2013-02-11'>
      <description>The "Guarani" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Guarani</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12424-8' platform='office2010' modified='2013-02-11'>
      <description>The "Malay (Brunei Darussalam)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Malay (Brunei Darussalam)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13441-1' platform='office2010' modified='2013-02-11'>
      <description>The "English (Indonesia)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\English (Indonesia)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11590-7' platform='office2010' modified='2013-02-11'>
      <description>The "Spanish (Bolivia)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Spanish (Bolivia)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14234-9' platform='office2010' modified='2013-02-11'>
      <description>The "Punjabi" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Punjabi</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12534-4' platform='office2010' modified='2013-02-11'>
      <description>The "Portuguese (Portugal)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Portuguese (Portugal)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13830-5' platform='office2010' modified='2013-02-11'>
      <description>The "English (Trinidad and Tobago)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\English (Trinidad and Tobago)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13117-7' platform='office2010' modified='2013-02-11'>
      <description>The "Arabic (Tunisia)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Arabic (Tunisia)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14929-4' platform='office2010' modified='2013-02-11'>
      <description>The "Bashkir" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Bashkir</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13217-5' platform='office2010' modified='2013-02-11'>
      <description>The "Arabic (Morocco)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Arabic (Morocco)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14104-4' platform='office2010' modified='2013-02-11'>
      <description>The "French (France)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\French (France)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14280-2' platform='office2010' modified='2013-02-11'>
      <description>The "Sami, Lule (Sweden)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Sami, Lule (Sweden)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13651-5' platform='office2010' modified='2013-02-11'>
      <description>The "Sanskrit" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Sanskrit</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13341-3' platform='office2010' modified='2013-02-11'>
      <description>The "Sami, Southern (Norway)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Sami, Southern (Norway)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12622-7' platform='office2010' modified='2013-02-11'>
      <description>The "Mohawk" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Mohawk</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14151-5' platform='office2010' modified='2013-02-11'>
      <description>The "Dari" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Dari</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14706-6' platform='office2010' modified='2013-02-11'>
      <description>The "Kinyarwanda" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Kinyarwanda</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12765-4' platform='office2010' modified='2013-02-11'>
      <description>The "Hausa (Latin)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Hausa (Latin)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13018-7' platform='office2010' modified='2013-02-11'>
      <description>The "French (West Indies)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\French (West Indies)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13415-5' platform='office2010' modified='2013-02-11'>
      <description>The "Arabic (Jordan)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Arabic (Jordan)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12934-6' platform='office2010' modified='2013-02-11'>
      <description>The "Chinese (Macao S.A.R.)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Chinese (Macao S.A.R.)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13811-5' platform='office2010' modified='2013-02-11'>
      <description>The "Estonian" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Estonian</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11546-9' platform='office2010' modified='2013-02-11'>
      <description>The "Punjabi (Pakistan)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Punjabi (Pakistan)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14548-2' platform='office2010' modified='2013-02-11'>
      <description>The "Arabic (Syria)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Arabic (Syria)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12406-5' platform='office2010' modified='2013-02-11'>
      <description>The "English (Philippines)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\English (Philippines)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14674-6' platform='office2010' modified='2013-02-11'>
      <description>The "English (U.S.)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\English (U.S.)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11684-8' platform='office2010' modified='2013-02-11'>
      <description>The "Icelandic" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Icelandic</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13819-8' platform='office2010' modified='2013-02-11'>
      <description>The "Sami, Inari (Finland)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Sami, Inari (Finland)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14585-4' platform='office2010' modified='2013-02-11'>
      <description>The "German (Luxembourg)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\German (Luxembourg)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12834-8' platform='office2010' modified='2013-02-11'>
      <description>The "English (Canada)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\English (Canada)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11970-1' platform='office2010' modified='2013-02-11'>
      <description>The "Albanian" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Albanian</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13620-0' platform='office2010' modified='2013-02-11'>
      <description>The "Lao" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Lao</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13360-3' platform='office2010' modified='2013-02-11'>
      <description>The "Italian (Italy)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Italian (Italy)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-11521-2' platform='office2010' modified='2013-02-11'>
      <description>The "French (Switzerland)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\French (Switzerland)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12228-3' platform='office2010' modified='2013-02-11'>
      <description>The "French (Reunion)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\French (Reunion)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12544-3' platform='office2010' modified='2013-02-11'>
      <description>The "Greenlandic" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Greenlandic</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13100-3' platform='office2010' modified='2013-02-11'>
      <description>The "Polish" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Polish</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12213-5' platform='office2010' modified='2013-02-11'>
      <description>The "isiXhosa" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\isiXhosa</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14723-1' platform='office2010' modified='2013-02-11'>
      <description>The "Arabic (Qatar)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Arabic (Qatar)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12826-4' platform='office2010' modified='2013-02-11'>
      <description>The "Spanish (Costa Rica)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Spanish (Costa Rica)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14397-4' platform='office2010' modified='2013-02-11'>
      <description>The "Occitan" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Occitan</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12318-2' platform='office2010' modified='2013-02-11'>
      <description>The "Filipino" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Filipino</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13199-5' platform='office2010' modified='2013-02-11'>
      <description>The "Serbian (Cyrillic, Serbia and Montenegro (Former))" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Serbian (Cyrillic, Serbia and Montenegro (Former))</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12756-3' platform='office2010' modified='2013-02-11'>
      <description>The "Indonesian" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Indonesian</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14918-7' platform='office2010' modified='2013-02-11'>
      <description>The "Oromo" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Oromo</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12837-1' platform='office2010' modified='2013-02-11'>
      <description>The "Breton" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Breton</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14727-2' platform='office2010' modified='2013-02-11'>
      <description>The "Malay (Malaysia)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Malay (Malaysia)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14562-3' platform='office2010' modified='2013-02-11'>
      <description>The "Burmese (Myanmar)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Burmese (Myanmar)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13349-6' platform='office2010' modified='2013-02-11'>
      <description>The "Corsican" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Corsican</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14144-0' platform='office2010' modified='2013-02-11'>
      <description>The "Sami, Lule (Norway)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Sami, Lule (Norway)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13572-3' platform='office2010' modified='2013-02-11'>
      <description>The "Croatian (Croatia)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Croatian (Croatia)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12433-9' platform='office2010' modified='2013-02-11'>
      <description>The "Slovenian" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Slovenian</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12864-5' platform='office2010' modified='2013-02-11'>
      <description>The "Latin" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Latin</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12981-7' platform='office2010' modified='2013-02-11'>
      <description>The "German (Liechtenstein)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\German (Liechtenstein)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14124-2' platform='office2010' modified='2013-02-11'>
      <description>The "Sesotho sa Leboa" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Sesotho sa Leboa</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12467-7' platform='office2010' modified='2013-02-11'>
      <description>The "Khmer" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Khmer</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14273-7' platform='office2010' modified='2013-02-11'>
      <description>The "Spanish (Chile)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Spanish (Chile)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12642-5' platform='office2010' modified='2013-02-11'>
      <description>The "Gujarati" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Gujarati</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13756-2' platform='office2010' modified='2013-02-11'>
      <description>The "Irish (Ireland)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Irish (Ireland)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14185-3' platform='office2010' modified='2013-02-11'>
      <description>The "Serbian (Cyrillic, Serbia)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Serbian (Cyrillic, Serbia)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12385-1' platform='office2010' modified='2013-02-11'>
      <description>The "English (Jamaica)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\English (Jamaica)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14493-1' platform='office2010' modified='2013-02-11'>
      <description>The "Sami, Northern (Norway)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Sami, Northern (Norway)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13183-9' platform='office2010' modified='2013-02-11'>
      <description>The "Japanese" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Japanese</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13678-8' platform='office2010' modified='2013-02-11'>
      <description>The "Sami, Northern (Finland)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Sami, Northern (Finland)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13948-5' platform='office2010' modified='2013-02-11'>
      <description>The "German (Switzerland)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\German (Switzerland)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14502-9' platform='office2010' modified='2013-02-11'>
      <description>The "Faeroese" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Faeroese</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12788-6' platform='office2010' modified='2013-02-11'>
      <description>The "Basque" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Basque</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13541-8' platform='office2010' modified='2013-02-11'>
      <description>The "Arabic (Kuwait)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Arabic (Kuwait)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12132-7' platform='office2010' modified='2013-02-11'>
      <description>The "Spanish (Mexico)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Spanish (Mexico)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12499-0' platform='office2010' modified='2013-02-11'>
      <description>The "Russian (Russia)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Russian (Russia)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14749-6' platform='office2010' modified='2013-02-11'>
      <description>The "Serbian (Cyrillic, Bosnia and Herzegovina)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Serbian (Cyrillic, Bosnia and Herzegovina)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13732-3' platform='office2010' modified='2013-02-11'>
      <description>The "Marathi" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Marathi</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12655-7' platform='office2010' modified='2013-02-11'>
      <description>The "English (India)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\English (India)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12674-8' platform='office2010' modified='2013-02-11'>
      <description>The "English (Malaysia)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\English (Malaysia)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13644-0' platform='office2010' modified='2013-02-11'>
      <description>The "Cherokee" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Cherokee</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14020-2' platform='office2010' modified='2013-02-11'>
      <description>The "Italian (Switzerland)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Italian (Switzerland)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12162-4' platform='office2010' modified='2013-02-11'>
      <description>The "isiZulu" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\isiZulu</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12326-5' platform='office2010' modified='2013-02-11'>
      <description>The "Nepali (India)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Nepali (India)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14462-6' platform='office2010' modified='2013-02-11'>
      <description>The "Chinese (Taiwan)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Chinese (Taiwan)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12075-8' platform='office2010' modified='2013-02-11'>
      <description>The "K'iche" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\K'iche</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14788-4' platform='office2010' modified='2013-02-11'>
      <description>The "Arabic (Lebanon)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Arabic (Lebanon)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13790-1' platform='office2010' modified='2013-02-11'>
      <description>The "French (Cote d'Ivoire)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\French (Cote d'Ivoire)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12758-9' platform='office2010' modified='2013-02-11'>
      <description>The "Lower Sorbian" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Lower Sorbian</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12224-2' platform='office2010' modified='2013-02-11'>
      <description>The "Latvian" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Latvian</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14668-8' platform='office2010' modified='2013-02-11'>
      <description>The "Romansh (Switzerland)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Romansh (Switzerland)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13507-9' platform='office2010' modified='2013-02-11'>
      <description>The "Bosnian (Latin, Bosnia and Herzegovina)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Bosnian (Latin, Bosnia and Herzegovina)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12172-3' platform='office2010' modified='2013-02-11'>
      <description>The "English (Zimbabwe)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\English (Zimbabwe)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12362-0' platform='office2010' modified='2013-02-11'>
      <description>The "English (New Zealand)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\English (New Zealand)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14786-8' platform='office2010' modified='2013-02-11'>
      <description>The "French (Mali)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\French (Mali)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12100-4' platform='office2010' modified='2013-02-11'>
      <description>The "English (U.K.)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\English (U.K.)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13212-6' platform='office2010' modified='2013-02-11'>
      <description>The "Spanish (Ecuador)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Spanish (Ecuador)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12669-8' platform='office2010' modified='2013-02-11'>
      <description>The "Dutch (Belgium)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Dutch (Belgium)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12109-5' platform='office2010' modified='2013-02-11'>
      <description>The "German (Austria)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\German (Austria)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13891-7' platform='office2010' modified='2013-02-11'>
      <description>The "Bulgarian" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Bulgarian</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12338-0' platform='office2010' modified='2013-02-11'>
      <description>The "French (Luxembourg)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\French (Luxembourg)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13003-9' platform='office2010' modified='2013-02-11'>
      <description>The "English (Singapore)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\English (Singapore)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13912-1' platform='office2010' modified='2013-02-11'>
      <description>The "Somali" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Somali</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12270-5' platform='office2010' modified='2013-02-11'>
      <description>The "Hebrew (Israel)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Hebrew (Israel)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13112-8' platform='office2010' modified='2013-02-11'>
      <description>The "Kyrgyz" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Kyrgyz</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14538-3' platform='office2010' modified='2013-02-11'>
      <description>The "Arabic (Bahrain)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Arabic (Bahrain)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12259-8' platform='office2010' modified='2013-02-11'>
      <description>The "Sami, Northern (Sweden)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Sami, Northern (Sweden)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12366-1' platform='office2010' modified='2013-02-11'>
      <description>The "Galician" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Galician</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12363-8' platform='office2010' modified='2013-02-11'>
      <description>The "Serbian (Cyrillic, Montenegro)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Serbian (Cyrillic, Montenegro)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14902-1' platform='office2010' modified='2013-02-11'>
      <description>The "English (Caribbean)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\English (Caribbean)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13434-6' platform='office2010' modified='2013-02-11'>
      <description>The "French (Morocco)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\French (Morocco)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12503-9' platform='office2010' modified='2013-02-11'>
      <description>The "Sindhi (Arabic)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Sindhi (Arabic)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-13603-6' platform='office2010' modified='2013-02-11'>
      <description>The "German (Germany)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\German (Germany)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-14436-0' platform='office2010' modified='2013-02-11'>
      <description>The "Luxembourgish (Luxembourg)" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Luxembourgish (Luxembourg)</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Microsoft Office 2010
SCM URL: http://go.microsoft.com/fwlink/?LinkId=113940</reference>
      </references>
    </cce>
    <cce cce_id='CCE-12484-2' platform='office2010' modified='2013-02-11'>
      <description>The "Mapudungun" common setting should be configured correctly.</description>
      <parameters>
        <parameter>enabled/disabled</parameter>
      </parameters>
      <technical_mechanisms>
        <technical_mechanism>User Configuration\Administrative Templates\Microsoft Office 2010\Language settings\Editing Languages\Enabled Editing Languages\Mapudungun</technical_mechanism>
        <technical_mechanism>HKEY_CURRENT_USER\software\policies\microsoft\office\14.0\common\languageresources\enabledlanguages</technical_mechanism>
      </technical_mechanisms>
      <references>
        <reference resource_id='Microsoft Security Compliance Manager (SCM) Baselines and Settings Packs'>Microsoft Tool: Security Compliance Manager (SCM)
Microsoft Baseline: Micros